competitor-teardown
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends installing the
belt-sh/clipackage vianpxand references installation instructions from a GitHub repository belonging to theinference-shorganization. - [COMMAND_EXECUTION]: The skill uses a set of shell commands through the
beltCLI to interact with research APIs and management functions. - [DYNAMIC_EXECUTION]: Includes a Python script template for generating a competitive positioning map, which is executed at runtime via a tool to produce a
.pngfile. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the web, including competitor sites and user reviews, creating a surface for injection. Ingestion points:
tavily/search-assistant,tavily/extract, andexa/searchinSKILL.md. Boundary markers: None identified. Capability inventory: Shell access viaBash(belt *)and file system writes via Python execution. Sanitization: None observed for the fetched research data.
Audit Metadata