personalized-storefront-render
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests internal artifacts and persona-specific lexicons to generate translated client storefronts, creating a surface for indirect instructions to influence agent behavior.
- Ingestion points: Reads artifact files from project directories (
/docs/**) and persona data from~/Documents/personas/. - Boundary markers: The skill instructions do not explicitly define delimiters or instructions to ignore embedded prompts within the source artifacts.
- Capability inventory: The skill has the ability to read and write files via the
organvmCLI and trigger deployment adapters (Next.js/Astro). - Sanitization: Employs a 'forbidden-term removal' mechanism and human ratification step, though these are focused on content quality rather than technical prompt injection mitigation.
- [COMMAND_EXECUTION]: The skill is designed to interface with the
organvmcommand-line utility for operations such assync,audit, andratify. This provides the agent with the capability to execute shell commands that interact with the local repository and the user's home directory (e.g.,~/Documents/personas/).
Audit Metadata