market-growth-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists purely of instructional Markdown and reference documentation. It contains no executable scripts, binaries, or active command-line tools.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting and analyzing external financial data, which creates a potential surface for indirect prompt injection. Ingestion points: The instructions direct the agent to analyze company filings, competitor reports, and industry datasets as primary evidence (referenced in references/methodology-router.md). Boundary markers: The skill lacks explicit markers or instructions to isolate or ignore potentially malicious instructions embedded within the external documents it is intended to process. Capability inventory: No capabilities for network requests, file system modification, or shell execution are defined within the skill's instruction set or referenced files. Sanitization: The methodology does not include steps for sanitizing or validating the integrity of the external content being analyzed.
- [SAFE]: All external references point to legitimate and well-known professional or academic domains, including mckinsey.com, hbs.edu, and morganstanley.com.
Audit Metadata