problem-validation

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting external content from the web for market research and competitor analysis.
  • Ingestion points: User-provided URLs for competitor analysis and automated search results from a background research agent in Phase 5 (Market Research).
  • Boundary markers: Absent. The agent is not explicitly instructed to ignore potential commands embedded within external website content.
  • Capability inventory: The skill has the ability to write and edit local files in the ./business/ directory and interact with the web using Chrome DevTools MCP tools (navigate_page, take_screenshot).
  • Sanitization: Absent. The skill does not define specific methods for filtering or sanitizing content retrieved from external URLs before it is processed.
  • [EXTERNAL_DOWNLOADS]: The skill leverages automated agents to fetch market data from the internet and utilizes external assets from shields.io for generating visual badges in business reports. These external references are legitimate and necessary for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM