positioning-map

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: No sensitive local files, credentials, or environment variables are accessed. The skill fetches public data from LinkedIn, the SEC, and marketing websites for research purposes.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving package installation, remote script execution (e.g., curl|bash), or dynamic code evaluation.
  • [COMMAND_EXECUTION]: The skill does not execute shell commands or interact with the local operating system.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites and social media posts. While this constitutes an attack surface, the risk is inherent to the skill's research function, and it lacks the high-privilege tools required for exploitation.
  • [PROMPT_INJECTION]: Instructions are focused on data extraction and synthesis; no attempts to override agent safety guidelines or extract system prompts were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:22 AM
Security Audit — agent-trust-hub — positioning-map