competitor-monitoring

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its core function of processing data from external, untrusted sources.
  • Ingestion points: The skill uses Chrome MCP to fetch content from competitor homepages, feature pages, pricing pages, and blogs. It also reads competitor lists from Google Drive.
  • Boundary markers: Absent. There are no delimiters or instructions provided to the agent to treat external content as untrusted or to ignore any malicious instructions that might be embedded in the competitor's web pages.
  • Capability inventory: The agent has permissions to read from and write to Google Drive, as well as browse the web via Chrome MCP. A successful injection could lead the agent to write malicious content or unintended summaries to the user's Drive.
  • Sanitization: Absent. The skill does not implement any validation or filtering of the content retrieved from external websites before incorporating it into the final Markdown report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 08:18 PM
Security Audit — agent-trust-hub — competitor-monitoring