competitor-watch

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external websites.
  • Ingestion points: External content is fetched via browser_json and browser_scrape as described in Step 2 of SKILL.md.
  • Boundary markers: No boundary markers or instructions to disregard embedded commands are present to mitigate risks from malicious instructions hidden in the scraped content.
  • Capability inventory: The skill utilizes browser tools to extract data which is then used to generate comparison reports.
  • Sanitization: There is no mention of sanitizing, validating, or filtering the content retrieved from external URLs before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 09:52 PM
Security Audit — agent-trust-hub — competitor-watch