persona-builder
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a vulnerability to indirect prompt injection by processing external, untrusted research data while maintaining file-write capabilities in Figma.
- Ingestion points: The skill defines 'Required Inputs' in
SKILL.mdthat include interview notes, survey data, support tickets, and external research repositories. - Boundary markers: The instructions do not define clear delimiters or specific guidance for the agent to ignore or isolate potentially malicious instructions embedded within the research data.
- Capability inventory: The skill is authorized to create artifacts, structure frames, and perform scoped edits within Figma design files (
SKILL.md). - Sanitization: There is no mention of sanitization, filtering, or validation of the input data to ensure it does not contain executable instructions or malicious prompts.
Audit Metadata