customer-persona

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt-sh/cli via npx and provides links to configuration/installation guidelines hosted on GitHub (inference-sh/skills). These are recognized as platform-specific vendor resources necessary for the skill's operation.
  • [COMMAND_EXECUTION]: The skill instructions include the use of the belt CLI tool to execute remote applications for market research (tavily/search-assistant, exa/search) and image generation (falai/flux-dev-lora). These executions are part of the core functionality for persona creation.
  • [PROMPT_INJECTION]: The skill ingests data from external search tools, which represents an indirect prompt injection surface. However, this is an inherent operational risk for any tool that processes search engine results and does not indicate a malicious intent within the skill itself.
  • Ingestion points: Data returned from tavily/search-assistant, exa/search, and exa/answer apps (SKILL.md).
  • Boundary markers: None explicitly defined in the prompt templates.
  • Capability inventory: Uses the Bash(belt *) tool to run external research and generation apps.
  • Sanitization: None detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — customer-persona