person-dossier

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several CLI tools including joelclaw, granola, and secrets to perform its workflow. These tools are used for querying email history, retrieving meeting transcripts, and managing session tokens. Based on the author context, these represent vendor-specific infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which creates a vulnerability surface for indirect instructions.
  • Ingestion points: Raw data is pulled from Front email threads and Granola meeting transcripts (SKILL.md Workflow steps 3 and 4).
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested content when generating the dossier.
  • Capability inventory: The skill has the ability to write to the local file system (Vault/Resources/) and access API tokens via a secrets service.
  • Sanitization: There are no explicit sanitization or filtering steps mentioned for the content extracted from emails or transcripts before it is incorporated into the final markdown dossier.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — person-dossier