persona-builder

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability to indirect prompt injection by processing external, untrusted research data while maintaining file-write capabilities in Figma.
  • Ingestion points: The skill defines 'Required Inputs' in SKILL.md that include interview notes, survey data, support tickets, and external research repositories.
  • Boundary markers: The instructions do not define clear delimiters or specific guidance for the agent to ignore or isolate potentially malicious instructions embedded within the research data.
  • Capability inventory: The skill is authorized to create artifacts, structure frames, and perform scoped edits within Figma design files (SKILL.md).
  • Sanitization: There is no mention of sanitization, filtering, or validation of the input data to ensure it does not contain executable instructions or malicious prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — persona-builder