skills/simota/agent-skills/cast/Gen Agent Trust Hub

cast

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting potentially untrusted data from repository files and external signals to synthesize persona attributes.
  • Ingestion points: Data is sourced from project files (README, documentation, source code, and tests) and handoffs from upstream agents (Field, Trace, Voice) as specified in reference/generation-workflows.md.
  • Boundary markers: Absent. The skill does not instruct the agent to use delimiters or specific ignore-instructions logic when processing these inputs.
  • Capability inventory: The agent can perform file system writes (.agents/personas/), execute local utility commands, and interact with network-based text-to-speech APIs.
  • Sanitization: Absent. There is no evidence of content filtering or sanitization of input data prior to persona generation.
  • [EXTERNAL_DOWNLOADS]: The skill relies on several well-known external libraries and services for its core functionality.
  • Evidence: References to the edge-tts package via npx and dependencies like pandas and scikit-learn for data clustering in reference/segmentation-methods.md.
  • Context: These are standard industry tools for text-to-speech and data analysis and are considered safe under established development practices.
  • [COMMAND_EXECUTION]: The skill executes local system commands to manage the environment and verify dependencies.
  • Evidence: Usage of curl, which, and npx to check for the presence of the VOICEVOX server and the macOS say utility in reference/speak-engine.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — cast