skills/inf-sh/skills/customer-persona/Gen Agent Trust Hub

customer-persona

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an installation script for the belt CLI tool located in the vendor's repository (inference-sh/skills). This is a standard procedure for configuring the required environment.
  • [COMMAND_EXECUTION]: The skill uses the belt CLI to perform market research using Tavily and Exa, and to generate persona avatars using Fal.ai. The execution of these commands is constrained to the belt utility via the frontmatter configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data retrieved from the web via search providers.
  • Ingestion points: Data enters the system from the output of tavily/search-assistant, exa/search, and exa/answer apps in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions that might be embedded in the retrieved web content.
  • Capability inventory: The skill has the capability to execute further tools via the belt CLI based on retrieved search data (SKILL.md).
  • Sanitization: No sanitization or filtering of external search results is specified before the agent incorporates the information into the persona template.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 04:34 AM
Security Audit — agent-trust-hub — customer-persona