Skip to content
Report library
Purpose / Other

Brandalf Skill Security Audit

What the author says it does (original text)

Guides creation, revision, and review of Warp- or Oz-branded assets. Use when working on launch pages, docs, HTML/CSS components, UI mockups, prompts, social assets, copy, presentations, or any other branded deliverable that should look and sound unmistakably Warp or Oz.

Independent security check

Security risks found

Files checked
1
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 1
Medium risk

A mutable external page is treated as authoritative instructions, enabling remote prompt injection

Source references: 6
What we found

The Skill requires the agent to fetch an external page for every branding task, treat it as the “source of truth,” and follow material that expressly includes “implementation guidance.” The supplied file pins no version or content hash, limits no permissible instruction types, and does not require treating the page only as reference data.

Why this matters

If the domain, deployment, or response is compromised or changed, the agent could accept new malicious or unauthorized directions as Skill rules, alter the user's assets, generate unsafe implementation details, or be induced into later actions. The available evidence does not show that the page is malicious or that any attack occurred.

The skill requires fetching an unpinned external webpage before brand work, treating its contents—including “implementation guidance”—as authoritative, and applying those rules to the output. If the page is compromised or later changed maliciously, an agent could treat out-of-scope webpage instructions as part of its workflow, affecting user files or decisions. The evidence supports this plausible risk, but does not show that the current page is malicious or that any attack occurred. Users can ask the author to pin a reviewed version or hash and explicitly limit remote content to brand reference material that cannot authorize commands, credential access, further network activity, or unrelated file changes.

SKILL.md:12In the instructionsOpen original file
The canonical brand skill lives at:`https://warp-brand-site.vercel.app/brand/skill`Before creating or revising any Warp- or Oz-branded asset, read that URL and use its contents as the source of truth for:
Show 5 other places
SKILL.md:22In the instructionsOpen original file
- voice and tone- component rules- naming and capitalization- implementation guidanceDo not rely on memory when the hosted skill can be fetched.
SKILL.md:30In the instructionsOpen original file
1. Fetch the hosted brand skill from `https://warp-brand-site.vercel.app/brand/skill`.2. Extract the guidance relevant to the asset being created.3. Apply those rules to the requested output.4. When presenting the result, briefly note any important brand constraints that materially shaped the output.
SKILL.md:14In the instructionsOpen original file
`https://warp-brand-site.vercel.app/brand/skill`
SKILL.md:16In the instructionsOpen original file
Before creating or revising any Warp- or Oz-branded asset, read that URL and use its contents as the source of truth for:
SKILL.md:24In the instructionsOpen original file
- naming and capitalization- implementation guidance
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

4 instruction sections

This Skill is an entry point for Warp and Oz branding work. Before creating or revising related assets, it requires fetching hosted brand guidance and applying relevant visual, copy, component, and implementation rules to the output.

View source
SKILL.md:16In the instructionsOpen original file
Before creating or revising any Warp- or Oz-branded asset, read that URL and use its contents as the source of truth for:- visual style- color usage- typography- voice and tone- component rules- naming and capitalization- implementation guidance
SKILL.md:30In the instructionsOpen original file
1. Fetch the hosted brand skill from `https://warp-brand-site.vercel.app/brand/skill`.2. Extract the guidance relevant to the asset being created.3. Apply those rules to the requested output.4. When presenting the result, briefly note any important brand constraints that materially shaped the output.

If the hosted guidance cannot be fetched, the Skill requires informing the user and letting them choose between best-effort guidance and retrying, rather than silently relying on memory.

View source
SKILL.md:44In the instructionsOpen original file
## If the source is unavailableIf the hosted skill cannot be fetched, say that the canonical branding source was unavailable and ask the user whether to proceed with best-effort branding guidance or to retry fetching it.
Start here · InstructionsSKILL.md
brandalf
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Connect to websites
SKILL.md:14In the instructionsOpen original file
`https://warp-brand-site.vercel.app/brand/skill`
SKILL.md:30In the instructionsOpen original file
1. Fetch the hosted brand skill from `https://warp-brand-site.vercel.app/brand/skill`.2. Extract the guidance relevant to the asset being created.
Lines read
47
File checksum (to compare versions)
ef1d3ddb90bc09cb4c82557318003fd7768845ab9348d83694428e615e389d52