product-persona-development
Warn
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: MEDIUMPROMPT_INJECTIONNO_CODESAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits extreme context bloating across multiple reference files, such as architecture-patterns.md and deployment-pipelines.md. These files contain a combined 1,200 sections of repetitive technical content entirely unrelated to the skill's purpose. This is an adversarial technique used to saturate the AI's context window, which can cause the model to ignore safety constraints or fail to follow primary instructions.- [PROMPT_INJECTION]: The skill employs deceptive metadata poisoning by claiming reference files are 'Ultimate Deep Dives' into persona development when they are actually generic technical templates. This consumes thousands of unnecessary tokens and hides the skill's true behavior.- [PROMPT_INJECTION]: The workflow involves ingesting untrusted external data (Step 2 and 3 of the research cycle) without establishing clear boundary markers or providing sanitization logic. This creates a vulnerability surface for indirect prompt injection through malicious research data.- [NO_CODE]: The skill is composed strictly of Markdown documentation and contains no executable scripts, installation commands, or external binary dependencies.- [SAFE]: The instructional content regarding empathy mapping, persona profiles, and feature mapping is based on valid product management frameworks and does not contain direct malicious logic.
Audit Metadata