corpus-persona-extraction
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data (session logs, chat exports) and performs complex NLP synthesis. This creates a surface for indirect prompt injection where malicious instructions embedded in logs could attempt to influence the synthesis of the
ideal_yearningorarchetypal_patternfields. - [DATA_EXFILTRATION]: While the skill explicitly instructs to 'Redact before analysis' and run secret/PII patterns, the core functionality involves extracting verbatim quotes from private logs into a persistent and potentially 'shareable'
{persona_id}.lexicon.yaml. If the redaction step fails or is incomplete, sensitive information (credentials, PII) could be exposed in the output lexicon.
Audit Metadata