persona-review
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external file content without sufficient isolation.\n
- Ingestion points: Document content is loaded from a user-provided file path in SKILL.md (Step 1).\n
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present when processing the file content.\n
- Capability inventory: The skill can modify the local filesystem by editing the original document (Step 6) and saving a review file (Step 7).\n
- Sanitization: There is no mention of sanitizing or escaping the content read from the document before it is processed by the agent.
Audit Metadata