personality-distiller

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability by using external, untrusted content to define future agent behavior.\n
  • Ingestion points: Web fetches and search results (SKILL.md, Types 1, 2, and 3).\n
  • Boundary markers: Absent; the skill does not instruct the agent to distinguish between source data and control instructions.\n
  • Capability inventory: Generates and overwrites core behavior-defining files in the workspace root, such as AGENTS.md and SOUL.md (SKILL.md, Phase 3).\n
  • Sanitization: Absent; external content is mapped directly to persona dimensions without validation.\n- [DATA_EXFILTRATION]: The skill is designed to read potentially sensitive user information from the local file system.\n
  • Evidence: Type 5 in SKILL.md ('Local Corpus') instructs the agent to read a user's notes, diaries, and other files to identify deep personal patterns like 'worries' and 'blind spots'. Accessing these files represents a data exposure risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:17 AM
Security Audit — agent-trust-hub — personality-distiller