positioning-map
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: No sensitive local files, credentials, or environment variables are accessed. The skill fetches public data from LinkedIn, the SEC, and marketing websites for research purposes.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving package installation, remote script execution (e.g., curl|bash), or dynamic code evaluation.
- [COMMAND_EXECUTION]: The skill does not execute shell commands or interact with the local operating system.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites and social media posts. While this constitutes an attack surface, the risk is inherent to the skill's research function, and it lacks the high-privilege tools required for exploitation.
- [PROMPT_INJECTION]: Instructions are focused on data extraction and synthesis; no attempts to override agent safety guidelines or extract system prompts were found.
Audit Metadata