brand-kit-assistant
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill incorporates comprehensive security practices, explicitly instructing the assistant to never expose or repeat authentication secrets, to require multi-step confirmation for destructive API operations, and to validate all generated content against defined brand guidelines.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface as it is designed to process external content from websites and file uploads.\n
- Ingestion points: User-provided Knowledge Vault source content, website URLs, and file uploads serve as untrusted data inputs (SKILL.md).\n
- Boundary markers: The instructions lack explicit delimiter-based markers to isolate untrusted data from processing logic (SKILL.md).\n
- Capability inventory: The assistant can perform state-changing API operations including resource creation, updates, and deletions for Brand Kits and Knowledge Vault (references/brand-kit-management-api-reference.md, references/knowledge-vault-api-reference-skill.md).\n
- Sanitization: The skill implements content validation against brand rules to mitigate risks from processed data (SKILL.md).
Audit Metadata