📦

brand

v1.0.0 مراجعة المحتوى r1 مخاطر متوسطة 📁 الوصول إلى نظام الملفات🌐 الوصول إلى الشبكة⚡ يحتوي على سكربتات⚙️ الأوامر الخارجية

Build consistent brand guidelines and assets

Brand work can become inconsistent across content, assets, and interfaces. This skill provides structured guidance, validation, and token synchronization to keep brand decisions aligned.

يدعم: Claude Codex Code(CC)
📊 74 كافٍ

التثبيت باستخدام Agent لدي

انسخ هذا الطلب إلى Agent لديك. يتضمن صفحة Skill المعتمدة وملف manifest.

طلب الوكيل
Review the Skillstore skill "brand" from https://skillstore.io/skills/nextlevelbuilder-brand.md and its manifest at https://skillstore.io/api/skills/nextlevelbuilder-brand/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

يجب أن يواصل Agent عرض خطته وطلب أي تأكيد تفرضه سياسة الأمان.

موارد مهيّأة لـ Agents

استخدم هذه الروابط عندما يحتاج AI Agent أو crawler أو script إلى سياق نظيف بدلًا من قراءة الصفحة كاملة.

اختبرها

جارٍ استخدام "brand". Create a voice guide for a reliable payroll service.

النتيجة المتوقعة:

  • Personality: clear, dependable, and helpful.
  • Tone: direct and reassuring.
  • Avoid: exaggerated claims and unexplained jargon.

جارٍ استخدام "brand". Review an image asset for brand compliance.

النتيجة المتوقعة:

  • Filename follows the campaign naming pattern.
  • PNG format and file size meet the defined limits.
  • Register the asset in the local manifest before approval.

جارٍ استخدام "brand". Define primary and accent colors for a product interface.

النتيجة المتوقعة:

  • Primary color: a clear blue for key actions.
  • Accent color: a contrasting green for success states.
  • Document accessible contrast checks before release.

التدقيق الأمني

مخاطر متوسطة

Most static detections are false positives caused by JavaScript template literals, regular expressions, documentation, and expected local file operations. One generated ImageMagick command can be unsafe to paste when an image filename is hostile. The prompt-context generator also requires reviewed guideline inputs because it emits their content as prompt-ready instructions.

18
الملفات التي تم فحصها
3,340
الأسطر التي تم تحليلها
1
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة

مخاوف أمنية مؤكدة (1)

متوسط
Untrusted guidelines can become prompt instructions
The context generator inserts extracted guideline fields, including a base prompt and style keywords, into prompt-ready output. A malicious or unreviewed guidelines file can therefore introduce instruction-like content into downstream AI prompts.
The generator accepts a caller-selected local guidelines path and directly interpolates extracted content into a prompt addition. This is intended functionality, but it establishes a clear trust boundary.
عناصر مراجعة القدرات (1)

هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.

متوسط
Ruby/shell backtick execution
return `magick "${imagePath}" -colors ${numColors} -depth 8 -format "%c" histogram:info:`;
The script emits an ImageMagick shell command with an unescaped image path inside double quotes. A hostile filename can execute shell substitutions if a user copies and runs the displayed command.

عوامل الخطر

📁 الوصول إلى نظام الملفات (29)
🌐 الوصول إلى الشبكة (4)
⚡ يحتوي على سكربتات (1)
⚙️ الأوامر الخارجية (50)
scripts/extract-colors.cjs:84 scripts/extract-colors.cjs:168 scripts/extract-colors.cjs:207 scripts/extract-colors.cjs:212 scripts/extract-colors.cjs:217 scripts/extract-colors.cjs:222 scripts/extract-colors.cjs:226 scripts/extract-colors.cjs:249 scripts/extract-colors.cjs:250 scripts/extract-colors.cjs:277 scripts/extract-colors.cjs:288 scripts/extract-colors.cjs:308 scripts/extract-colors.cjs:309 scripts/extract-colors.cjs:316 scripts/extract-colors.cjs:317 scripts/extract-colors.cjs:318 scripts/inject-brand-context.cjs:193-195 scripts/inject-brand-context.cjs:195 scripts/inject-brand-context.cjs:245-248 scripts/inject-brand-context.cjs:248 scripts/inject-brand-context.cjs:251 scripts/inject-brand-context.cjs:286-290 scripts/inject-brand-context.cjs:296-299 scripts/inject-brand-context.cjs:302-322 scripts/inject-brand-context.cjs:322-323 scripts/sync-brand-to-tokens.cjs:14 scripts/sync-brand-to-tokens.cjs:238 scripts/sync-brand-to-tokens.cjs:48 scripts/sync-brand-to-tokens.cjs:54 scripts/sync-brand-to-tokens.cjs:58 scripts/sync-brand-to-tokens.cjs:73 scripts/sync-brand-to-tokens.cjs:110 scripts/sync-brand-to-tokens.cjs:118 scripts/sync-brand-to-tokens.cjs:135 scripts/sync-brand-to-tokens.cjs:151 scripts/sync-brand-to-tokens.cjs:152 scripts/sync-brand-to-tokens.cjs:153 scripts/sync-brand-to-tokens.cjs:154 scripts/sync-brand-to-tokens.cjs:155 scripts/sync-brand-to-tokens.cjs:156 scripts/sync-brand-to-tokens.cjs:159 scripts/sync-brand-to-tokens.cjs:160 scripts/sync-brand-to-tokens.cjs:161 scripts/sync-brand-to-tokens.cjs:162 scripts/sync-brand-to-tokens.cjs:165 scripts/sync-brand-to-tokens.cjs:166 scripts/sync-brand-to-tokens.cjs:167 scripts/sync-brand-to-tokens.cjs:170 scripts/sync-brand-to-tokens.cjs:171 scripts/sync-brand-to-tokens.cjs:172
دقّقه: claude
شارك واستشهد بهذا التقرير

شارك تقرير التقييم المرتبط بالإصدار والشارة المحايدة وبطاقة التضمين والاستشهادات. تعرض Skillstore الأدلة من دون أن تقرر ما إذا كانت هذه المهارة آمنة.

فتح التقرير المرتبط بالإصدار
تقييم الأمان

نسخ رابط التقرير

https://skillstore.io/skills/nextlevelbuilder-brand/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

شارة Markdown

[![Skillstore security assessment](https://skillstore.io/badges/skills/nextlevelbuilder-brand/security.svg)](https://skillstore.io/skills/nextlevelbuilder-brand?utm_source=security_passport_badge)

شارة HTML

<a href="https://skillstore.io/skills/nextlevelbuilder-brand?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/nextlevelbuilder-brand/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

بطاقة قابلة للتضمين

<iframe src="https://skillstore.io/embed/skills/nextlevelbuilder-brand.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
الاستشهادات الأكاديمية (APA · BibTeX · CFF)

اقتباس APA

nextlevelbuilder. (2026). brand security audit report (audit version 1) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/nextlevelbuilder-brand/audits/1

اقتباس BibTeX

@techreport{nextlevelbuilder-nextlevelbuilder-brand-2026, author = {nextlevelbuilder}, title = {brand security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/nextlevelbuilder-brand/audits/1}, note = {Author version 1.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "brand security audit report (audit version 1)" version: "1.0.0" type: report authors: - name: "nextlevelbuilder" date-released: "2026-09-11" url: "https://skillstore.io/skills/nextlevelbuilder-brand/audits/1" identifiers: - type: other value: "skillstore:nextlevelbuilder-brand:audit:1" description: "Skillstore immutable audit report identifier"

تقييم Skillstore

سبب هذا التقييم موثوقية الأدلة: متوسط
68
الهندسة المعمارية
100
قابلية الصيانة
87
المحتوى
65
المجتمع
83
الامتثال للمواصفات

ما الذي يمكنك بناؤه

Define a new brand voice

Create a clear voice framework and messaging guidance for a new product launch.

Review campaign assets

Check local asset names, formats, sizes, and registration before campaign delivery.

Align interface tokens

Transfer documented brand colors into local design tokens for a product interface.

جرّب هذه الموجّهات

Create a brand voice
Create a concise brand voice guide for [brand]. Include personality, tone, preferred language, and prohibited terms.
Draft brand guidelines
Create brand guidelines for [brand] using [audience], [mission], [colors], and [typefaces]. Include visual and messaging standards.
Review brand consistency
Review these campaign materials against our brand guidelines. List inconsistencies, explain each issue, and recommend precise corrections.
Update design tokens
Update our brand guidelines with these color decisions, then prepare the local design-token synchronization workflow. Use a dry run first.

أفضل الممارسات

  • Keep one reviewed brand-guidelines file as the source of truth.
  • Run token synchronization with a dry run before writing project files.
  • Review generated brand content with the responsible brand owner.

تجنب

  • Do not treat generated messaging as legal or trademark advice.
  • Do not paste suggested shell commands for filenames you do not trust.
  • Do not overwrite design tokens without reviewing the proposed changes.

الأسئلة المتكررة

What does this skill help with?
It supports brand voice, visual identity, messaging, asset standards, and token workflows.
Which tools can use this skill?
The package declares support for Claude, Codex, and Claude Code.
Does it analyze image pixels directly?
No. It prepares color comparison guidance and can use a separate image-analysis tool.
Can it update design tokens?
Yes. Its sync script updates local token files from documented brand colors.
Does asset validation modify files?
No. The validator reports issues and filename suggestions without renaming assets.
Should I trust injected brand context automatically?
Use only reviewed guidelines files because their content is included in prompt-ready output.

تفاصيل المطور

المؤلف

nextlevelbuilder

الترخيص

MIT

إصدار المؤلف

v1.0.0

مراجعة Skillstore

r1

مرجع

ab32f1e771b01001f924c38df083d099af94056e

حداثة الصيانة

١١‏/٩‏/٢٠٢٦

الاستخدام

0 تنزيلات · 0 مشاهدات