create-persona
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill interacts with well-known external services to gather data for persona creation. Evidence:
src/voice.pyandbatch_ingest.pydownload audio and transcripts from YouTube using theingest-youtubeskill.src/research.pyperforms metadata searches on ArXiv. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection due to its core functionality of processing external data. (1) Ingestion points: Data is ingested from YouTube transcripts, ArXiv papers, and web search results in
batch_ingest.pyandsrc/research.py. (2) Boundary markers: The current implementation does not utilize explicit delimiters or specialized safety headers when passing this external content into the agent's context. (3) Capability inventory: The skill can invoke other system skills viasubprocess.runand write files to the local file system. (4) Sanitization: No explicit text sanitization or filtering logic was identified for these ingested streams.
Audit Metadata