brandalf

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch data from an external URL (https://warp-brand-site.vercel.app/brand/skill) to serve as a source of truth for branding workflows.
  • Ingestion points: SKILL.md (fetches content from https://warp-brand-site.vercel.app/brand/skill at runtime).
  • Boundary markers: Absent; there are no explicit delimiters or instructions guiding the agent to ignore any potential embedded prompt injections within the fetched content.
  • Capability inventory: No specific script capabilities or advanced tool executions are shipped within the skill itself.
  • Sanitization: Absent; the skill does not define validation or sanitization mechanisms for the external text content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:39 AM
Security Audit — agent-trust-hub — brandalf