monitor-personas
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches content from various external services including YouTube (via yt-dlp), RSS feeds, and arXiv research papers as defined in 'personas.yaml'.
- [COMMAND_EXECUTION]: The skill frequently executes local shell scripts ('run.sh') and system utilities ('curl', 'ps', 'yt-dlp') via subprocess calls to interact with sibling skills (taxonomy, memory, doc2qra, extractor) and manage local processes.
- [PROMPT_INJECTION]: The skill processes untrusted external content (transcripts, feed items, research abstracts) that is subsequently passed to LLM-driven skills like 'doc2qra' and 'taxonomy'. This creates a surface for indirect prompt injection where malicious instructions embedded in the external content could influence the behavior of the processing skills.
- Ingestion points: content handlers in 'sources.py' (YouTube, RSS, arXiv) and discovery logic in 'curate.py' (Movies, Books, Music, Arxiv, Security, Dogpile).
- Boundary markers: No explicit instruction delimiters or 'ignore embedded instructions' warnings are applied to the text before processing by LLM-dependent integrations.
- Capability inventory: Execution of shell scripts and system tools via 'integrations.py' and 'monitor_commands.py', and database interaction via AQL queries in 'run.sh'.
- Sanitization: Content is truncated (typically to 3000-4000 characters) but not otherwise sanitized before ingestion.
Audit Metadata