customer-persona

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for market research and persona creation, using established patterns for data gathering and visual generation without malicious intent.
  • [EXTERNAL_DOWNLOADS]: References installation instructions for the vendor's CLI tool from their official GitHub repository.
  • [COMMAND_EXECUTION]: Executes the infsh CLI tool for search and image generation tasks, which is explicitly permitted and scoped within the skill's manifest.
  • [PROMPT_INJECTION]: Contains a surface for indirect prompt injection as it processes content from external search engines (Tavily, Exa). This is a known risk inherent to web-research skills and is documented here as a functional characteristic rather than a vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 07:30 PM