create-persona

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with well-known external services to gather data for persona creation. Evidence: src/voice.py and batch_ingest.py download audio and transcripts from YouTube using the ingest-youtube skill. src/research.py performs metadata searches on ArXiv.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection due to its core functionality of processing external data. (1) Ingestion points: Data is ingested from YouTube transcripts, ArXiv papers, and web search results in batch_ingest.py and src/research.py. (2) Boundary markers: The current implementation does not utilize explicit delimiters or specialized safety headers when passing this external content into the agent's context. (3) Capability inventory: The skill can invoke other system skills via subprocess.run and write files to the local file system. (4) Sanitization: No explicit text sanitization or filtering logic was identified for these ingested streams.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — create-persona