company-insight

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection. It ingests untrusted content from the internet using WebSearch and WebFetch tools to perform company research. Without specific boundary markers or instructions to disregard embedded commands, the agent could potentially follow malicious instructions found on researched websites.
  • Ingestion points: External website content retrieved via WebSearch and WebFetch (SKILL.md).
  • Boundary markers: Absent. The instructions do not use delimiters or explicit warnings to the agent to treat fetched content as data only.
  • Capability inventory: Write, Edit, Bash, and various MCP tools for writing to channels (SKILL.md).
  • Sanitization: Absent. There is no evidence of filtering or validating the external content before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 05:36 AM
Security Audit — agent-trust-hub — company-insight