competitor-watch
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external websites.
- Ingestion points: External content is fetched via
browser_jsonandbrowser_scrapeas described in Step 2 ofSKILL.md. - Boundary markers: No boundary markers or instructions to disregard embedded commands are present to mitigate risks from malicious instructions hidden in the scraped content.
- Capability inventory: The skill utilizes browser tools to extract data which is then used to generate comparison reports.
- Sanitization: There is no mention of sanitizing, validating, or filtering the content retrieved from external URLs before the agent processes it.
Audit Metadata