market-scan

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from competitor websites and writes the resulting analysis back to local project files, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The agent is directed to scan external competitor homepages, changelogs, pricing pages, and launch posts (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters, XML tags, or other isolation techniques to separate external data from the agent's core instructions, although it suggests tagging findings as [assumption] for manual review.
  • Capability inventory: The agent has the capability to read local files (docs/gtm-cofounder/founder-brief.md), browse/search the web, and write updates to local markdown files (docs/gtm-cofounder/founder-brief.md and docs/gtm-cofounder/gtm-roadmap.md).
  • Sanitization: The skill lacks explicit instructions to sanitize, escape, or validate content retrieved from external websites before it is processed or written to the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 01:13 PM
Security Audit — agent-trust-hub — market-scan