customer-persona
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a guide for market research and persona creation. Its operations are consistent with its description and intended use case.
- [EXTERNAL_DOWNLOADS]: The instructions recommend installing the belt CLI via npx and adding skills from the inference-sh organization. These are legitimate resources provided by the tool's authors.
- [COMMAND_EXECUTION]: The skill utilizes the belt CLI to execute remote apps for searching and image generation. These commands are restricted to the allowed-tools scope and perform expected functions.
- [DATA_EXFILTRATION]: While the skill fetches data from external search providers (Tavily, Exa), this is a standard requirement for market research and does not involve unauthorized access to or transmission of sensitive local data.
- [PROMPT_INJECTION]: Indirect prompt injection attack surface identified. Ingestion points: Output from tavily/search-assistant and exa/search apps in SKILL.md. Boundary markers: Absent. Capability inventory: belt app run (subprocess) in SKILL.md. Sanitization: Absent. This represents a low-risk surface inherent to web-research skills.
Audit Metadata