corpus-persona-extraction

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data (session logs, chat exports) and performs complex NLP synthesis. This creates a surface for indirect prompt injection where malicious instructions embedded in logs could attempt to influence the synthesis of the ideal_yearning or archetypal_pattern fields.
  • [DATA_EXFILTRATION]: While the skill explicitly instructs to 'Redact before analysis' and run secret/PII patterns, the core functionality involves extracting verbatim quotes from private logs into a persistent and potentially 'shareable' {persona_id}.lexicon.yaml. If the redaction step fails or is incomplete, sensitive information (credentials, PII) could be exposed in the output lexicon.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:27 AM
Security Audit — agent-trust-hub — corpus-persona-extraction