brand-kit-assistant

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill incorporates comprehensive security practices, explicitly instructing the assistant to never expose or repeat authentication secrets, to require multi-step confirmation for destructive API operations, and to validate all generated content against defined brand guidelines.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface as it is designed to process external content from websites and file uploads.\n
  • Ingestion points: User-provided Knowledge Vault source content, website URLs, and file uploads serve as untrusted data inputs (SKILL.md).\n
  • Boundary markers: The instructions lack explicit delimiter-based markers to isolate untrusted data from processing logic (SKILL.md).\n
  • Capability inventory: The assistant can perform state-changing API operations including resource creation, updates, and deletions for Brand Kits and Knowledge Vault (references/brand-kit-management-api-reference.md, references/knowledge-vault-api-reference-skill.md).\n
  • Sanitization: The skill implements content validation against brand rules to mitigate risks from processed data (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:43 PM
Security Audit — agent-trust-hub — brand-kit-assistant