gtm-persona

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Git commands, including commit, add, and branch management, to persist persona definitions and maintain workspace history. These operations are restricted to specific persona paths and the main branch.
  • [EXTERNAL_DOWNLOADS]: The skill performs Git synchronization through pull operations to maintain repository state with remote servers.
  • [PROMPT_INJECTION]: The skill processes potentially untrusted data from persona artifacts and organization definitions, creating a surface for indirect prompt injection. 1. Ingestion points: Reads markdown files and persona facts from connected repositories or the ~/.gtm/ directory. 2. Boundary markers: Employs node-local visibility rules and a factual ceiling policy to prevent external content from overriding instructions. 3. Capability inventory: Includes file modification (create, update, delete) and repository history management (Git commit and push). 4. Sanitization: Features a Link Safety protocol to detect and filter URLs containing authentication tokens or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:42 AM
Security Audit — agent-trust-hub — gtm-persona