person-dossier
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several CLI tools including
joelclaw,granola, andsecretsto perform its workflow. These tools are used for querying email history, retrieving meeting transcripts, and managing session tokens. Based on the author context, these represent vendor-specific infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which creates a vulnerability surface for indirect instructions.
- Ingestion points: Raw data is pulled from Front email threads and Granola meeting transcripts (
SKILL.mdWorkflow steps 3 and 4). - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested content when generating the dossier.
- Capability inventory: The skill has the ability to write to the local file system (
Vault/Resources/) and access API tokens via a secrets service. - Sanitization: There are no explicit sanitization or filtering steps mentioned for the content extracted from emails or transcripts before it is incorporated into the final markdown dossier.
Audit Metadata