customer-persona
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for market research and persona creation, using established patterns for data gathering and visual generation without malicious intent.
- [EXTERNAL_DOWNLOADS]: References installation instructions for the vendor's CLI tool from their official GitHub repository.
- [COMMAND_EXECUTION]: Executes the
infshCLI tool for search and image generation tasks, which is explicitly permitted and scoped within the skill's manifest. - [PROMPT_INJECTION]: Contains a surface for indirect prompt injection as it processes content from external search engines (Tavily, Exa). This is a known risk inherent to web-research skills and is documented here as a functional characteristic rather than a vulnerability.
Audit Metadata