competitor-teardown
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script
scripts/momentum_score.pyto process research data. This script is part of the skill package and performs deterministic scoring logic without external network dependencies or sensitive file access. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the public web which constitutes a potential attack surface.
- Ingestion points: The agent uses
web_scrape,google_news,amazon_reviews, andyoutube_commentsto fetch content from the public web inSKILL.md(Step 2). - Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the fetched content.
- Capability inventory: The agent has access to research tools and shell execution for the momentum scoring script.
- Sanitization: No explicit sanitization or escaping of the scraped text is mentioned before it is processed by the agent.
Audit Metadata