competitor-tracker

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates within defined memory paths (memory/influencer/competitor-tracker/) and uses legitimate scripts for news and RSS monitoring. The use of GDELT (gdelt.py) for news indexing and RSS for YouTube monitoring is consistent with public data analysis and does not involve credential theft or unauthorized data access.- [SAFE]: Instructions direct the agent to propose updates to a creator registry through an authorized internal protocol (registry-events.py), which is a structured and controlled method for inter-skill communication.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill mentions placeholders for tools like ~~social platform analytics and ~~CRM, but these are used as conceptual connectors for the agent rather than active malicious scripts. No sensitive files (e.g., .ssh, .aws) or hardcoded credentials were detected.
  • [REMOTE_CODE_EXECUTION]: External scripts like gdelt.py and youtube.py are referenced from the project's own root directory (${CLAUDE_PLUGIN_ROOT}/scripts/), which is standard for modular agent skills. No downloads from untrusted third-party servers or piped executions (e.g., curl | bash) were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:28 PM
Security Audit — agent-trust-hub — competitor-tracker