market-growth-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists purely of instructional Markdown and reference documentation. It contains no executable scripts, binaries, or active command-line tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting and analyzing external financial data, which creates a potential surface for indirect prompt injection. Ingestion points: The instructions direct the agent to analyze company filings, competitor reports, and industry datasets as primary evidence (referenced in references/methodology-router.md). Boundary markers: The skill lacks explicit markers or instructions to isolate or ignore potentially malicious instructions embedded within the external documents it is intended to process. Capability inventory: No capabilities for network requests, file system modification, or shell execution are defined within the skill's instruction set or referenced files. Sanitization: The methodology does not include steps for sanitizing or validating the integrity of the external content being analyzed.
  • [SAFE]: All external references point to legitimate and well-known professional or academic domains, including mckinsey.com, hbs.edu, and morganstanley.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 01:32 PM
Security Audit — agent-trust-hub — market-growth-intelligence