Back to skill

Security audit

brand-identity-design

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent brand identity design workflow skill with no hidden execution, credential use, network behavior, or persistence.

This skill is appropriate to install for structured brand visual identity work. Expect it to guide the agent through a strict staged design process and possibly produce design notes or files when you ask for deliverables, but I found no evidence of hidden execution, data access, or persistence.

Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This manifest-style eval file contains a full evaluation case written in Chinese, which imposes a specific language context in the skill artifacts without any accompanying note that language is user-selectable or region-specific. Under the language/locale policy rule, forcing a specific language without opt-in can be a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
This JSON file contains a Chinese-language prompt alongside English-language content, but there is no accompanying natural-language indication that the skill supports multiple languages by user choice. Under the locale/language policy rule, hardcoding a specific language without documented opt-in can be a policy concern.

Static analysis

No suspicious patterns detected.