audience-research

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or unauthorized behaviors were detected. The skill's operations are confined to reading and writing branding documentation in the local project directory.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes a search tool (Exa MCP) to identify public online communities and customer feedback. This is a functional requirement for market research and does not involve the execution of untrusted remote code.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from web search results (such as Reddit posts or review sites) to generate personas.
  • Ingestion points: Web data gathered via the Exa MCP tool as described in 'The audience research process'.
  • Boundary markers: Not explicitly specified in the instruction prompt interpolation.
  • Capability inventory: Reading local markdown files and writing to './brand/audience.md' and './brand/learnings.md'.
  • Sanitization: The skill includes safety rules instructing the agent to never fabricate quotes and to mark paraphrased content as 'representative', reducing the risk of generating misleading or malicious output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — audience-research