customer-persona

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a guide for market research and persona creation. Its operations are consistent with its description and intended use case.
  • [EXTERNAL_DOWNLOADS]: The instructions recommend installing the belt CLI via npx and adding skills from the inference-sh organization. These are legitimate resources provided by the tool's authors.
  • [COMMAND_EXECUTION]: The skill utilizes the belt CLI to execute remote apps for searching and image generation. These commands are restricted to the allowed-tools scope and perform expected functions.
  • [DATA_EXFILTRATION]: While the skill fetches data from external search providers (Tavily, Exa), this is a standard requirement for market research and does not involve unauthorized access to or transmission of sensitive local data.
  • [PROMPT_INJECTION]: Indirect prompt injection attack surface identified. Ingestion points: Output from tavily/search-assistant and exa/search apps in SKILL.md. Boundary markers: Absent. Capability inventory: belt app run (subprocess) in SKILL.md. Sanitization: Absent. This represents a low-risk surface inherent to web-research skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 08:29 PM
Security Audit — agent-trust-hub — customer-persona