persona-review

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external file content without sufficient isolation.\n
  • Ingestion points: Document content is loaded from a user-provided file path in SKILL.md (Step 1).\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present when processing the file content.\n
  • Capability inventory: The skill can modify the local filesystem by editing the original document (Step 6) and saving a review file (Step 7).\n
  • Sanitization: There is no mention of sanitizing or escaping the content read from the document before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 01:02 PM
Security Audit — agent-trust-hub — persona-review