monitor-personas

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from various external services including YouTube (via yt-dlp), RSS feeds, and arXiv research papers as defined in 'personas.yaml'.
  • [COMMAND_EXECUTION]: The skill frequently executes local shell scripts ('run.sh') and system utilities ('curl', 'ps', 'yt-dlp') via subprocess calls to interact with sibling skills (taxonomy, memory, doc2qra, extractor) and manage local processes.
  • [PROMPT_INJECTION]: The skill processes untrusted external content (transcripts, feed items, research abstracts) that is subsequently passed to LLM-driven skills like 'doc2qra' and 'taxonomy'. This creates a surface for indirect prompt injection where malicious instructions embedded in the external content could influence the behavior of the processing skills.
  • Ingestion points: content handlers in 'sources.py' (YouTube, RSS, arXiv) and discovery logic in 'curate.py' (Movies, Books, Music, Arxiv, Security, Dogpile).
  • Boundary markers: No explicit instruction delimiters or 'ignore embedded instructions' warnings are applied to the text before processing by LLM-dependent integrations.
  • Capability inventory: Execution of shell scripts and system tools via 'integrations.py' and 'monitor_commands.py', and database interaction via AQL queries in 'run.sh'.
  • Sanitization: Content is truncated (typically to 3000-4000 characters) but not otherwise sanitized before ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:40 AM
Security Audit — agent-trust-hub — monitor-personas