personalized-storefront-render

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests internal artifacts and persona-specific lexicons to generate translated client storefronts, creating a surface for indirect instructions to influence agent behavior.
  • Ingestion points: Reads artifact files from project directories (/docs/**) and persona data from ~/Documents/personas/.
  • Boundary markers: The skill instructions do not explicitly define delimiters or instructions to ignore embedded prompts within the source artifacts.
  • Capability inventory: The skill has the ability to read and write files via the organvm CLI and trigger deployment adapters (Next.js/Astro).
  • Sanitization: Employs a 'forbidden-term removal' mechanism and human ratification step, though these are focused on content quality rather than technical prompt injection mitigation.
  • [COMMAND_EXECUTION]: The skill is designed to interface with the organvm command-line utility for operations such as sync, audit, and ratify. This provides the agent with the capability to execute shell commands that interact with the local repository and the user's home directory (e.g., ~/Documents/personas/).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — personalized-storefront-render