competitor-spy

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests and processes untrusted data from external URLs during the competitor analysis phase. This represents a potential surface for indirect prompt injection, though it is necessary for the skill's functionality.
  • Ingestion points: web_fetch operations on competitor websites in Step 2.
  • Capability inventory: web_search, web_fetch.
  • Boundary markers: Not specified.
  • Sanitization: Not specified.
  • [DATA_EXFILTRATION]: The skill references list.affitor.com to validate affiliate programs. This is a known resource associated with the author 'affitor' and is used as intended for program discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 08:53 AM