market-comparison

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external neighbor artifacts which serve as an attack surface for indirect instructions. * Ingestion points: MARKET-MAP.md (Ticket [2] and [6]) instructions use free-search fetch to retrieve untrusted content from external URLs. * Boundary markers: The ticket templates do not specify the use of delimiters or 'ignore' instructions for fetched content. * Capability inventory: The skill manages tasks via wayfinder, updates issue states with bd, and writes to the local .arc/market/ directory. * Sanitization: There is no indication that external data is sanitized or validated prior to processing.
  • [COMMAND_EXECUTION]: The rubric construction process allows for evidence based on script execution. * Evidence: The rubric examples in SKILL.md and RUBRICS.md demonstrate the use of a local benchmark script ./bench.sh as evidence for performance scores.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to retrieve competitor artifacts from arbitrary external domains. * Evidence: MARKET-MAP.md (Ticket [2]) directs the agent to profile solutions by URL and fetch their content for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — market-comparison