benchmark-methodology

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external sources such as competitor websites, LinkedIn, and review directories (e.g., Clutch.co). While this represents a surface for indirect prompt injection if those sites contain malicious instructions, the skill does not possess high-risk capabilities (like system command execution or sensitive file writes) that would be exploitable through this vector. The instructions focus on analytical scoring and evidence-anchored reporting.
  • Ingestion points: External competitor websites, project case studies, review directories, and social media profiles.
  • Boundary markers: Not explicitly defined in the methodology.
  • Capability inventory: None detected. The skill provides formatting and scoring guidelines without calling external tools or executing scripts.
  • Sanitization: None described for ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:39 AM
Security Audit — agent-trust-hub — benchmark-methodology