persona-generator
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill contains inconsistent and misleading information in its 'Skill Boundaries' section. While the document's primary purpose is buyer persona generation, the boundaries section describes capabilities and limitations related to 'audio production workflows' and 'audio engineering expertise.' This indicates a significant metadata inconsistency that misrepresents the skill's actual scope and functionality.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, specifically customer interview notes and existing persona documents, without sufficient isolation or sanitization.
- Ingestion points: Data enters the agent's context through user-provided summaries of customer interviews and pasted persona text as described in the 'How to Use' section of SKILL.md.
- Boundary markers: The instructions do not define clear delimiters or use specialized syntax to encapsulate user-supplied content, increasing the risk that instructions embedded within interview notes could influence the agent's behavior.
- Capability inventory: The skill is primarily designed for text generation and analysis; it does not contain identified network operations, file system modifications, or subprocess executions.
- Sanitization: The methodology lacks steps for validating or filtering the content of processed interview data before it is used to generate persona reports.
Audit Metadata