competitive-teardown
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from competitor websites, social media, and app store reviews.
- Ingestion points: Workflow instructions in SKILL.md and references/data-collection-guide.md direct the agent to fetch raw content from third-party URLs and platforms.
- Boundary markers: The skill does not specify the use of delimiters or boundary instructions to isolate external content from the agent's core instructions.
- Capability inventory: The agent uses localized template files and a provided Python scoring utility (scripts/competitive_matrix_builder.py).
- Sanitization: No explicit sanitization or filtering steps are defined for the ingested text.- [EXTERNAL_DOWNLOADS]: The skill references official iTunes Search API endpoints (itunes.apple.com) for retrieving competitor metadata and customer reviews. This is a transparent use of a well-known service for its intended purpose.- [COMMAND_EXECUTION]: The package includes a Python script (scripts/competitive_matrix_builder.py) for generating weighted comparison matrices. The script relies solely on standard Python libraries and processes locally provided data.
Audit Metadata