persona-insights-analysis

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Indirect injection surface detected. The skill ingests raw, untrusted data from multiple sources (MCP, CSV, Text, PDF) to perform analysis and report generation.
  • Ingestion points: Phase 2, Sources A, B, C, and D in SKILL.md.
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore embedded instructions within transcripts.
  • Capability inventory: High-level analysis, data synthesis, and React artifact generation.
  • Sanitization: Absent. The instructions do not define methods for escaping or validating transcript content before processing.
  • [EXTERNAL_DOWNLOADS]: The skill includes a feature to fetch content from arbitrary URLs provided by the user. Specifically, Source B in Phase 2 states: "If the transcript column contains a URL → fetch the transcript content from that URL."
  • [DATA_EXFILTRATION]: While intended for ingestion, the combination of fetching from arbitrary URLs and accessing sensitive data from MCP tools (Gong, Chorus, etc.) creates a potential risk for data exposure if the agent is manipulated via malicious input.
  • [PROMPT_INJECTION]: The skill generates interactive React artifacts (dashboards) based on analysis. If the input data (transcripts) contains malicious instructions or scripts that are quoted as verbatims, it could lead to the execution of unwanted code within the generated artifact's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:21 PM
Security Audit — agent-trust-hub — persona-insights-analysis