customer-persona
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references external setup guides and suggests installing the
belt-sh/cliNode.js package from an external repository. - [COMMAND_EXECUTION]: The skill uses the
beltcommand-line utility via Bash to execute market research and image generation tools. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes data from external search providers.
- Ingestion points: Output from
tavily/search-assistantandexa/searchtools are used to build the persona. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present.
- Capability inventory: Bash execution permissions for the
beltCLI tool. - Sanitization: The skill does not specify sanitization or validation of the results returned by the research tools.
Audit Metadata