compete

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate file operations within the project scope by reading from the 'propositions/' directory and 'portfolio.json' and writing results to the 'competitors/' directory.
  • [SAFE]: Research functionality is delegated to a separate internal tool ('competitor-researcher'), which is a standard pattern for multi-agent workflows and does not represent a direct security risk.
  • [SAFE]: Analysis of the instructions and operational logic shows no signs of prompt injection, obfuscation, or unauthorized data exfiltration.
  • [SAFE]: Indirect Prompt Injection Risk Assessment: 1. Ingestion points: Files in 'propositions/' directory, 'portfolio.json', and output from the 'competitor-researcher' agent. 2. Boundary markers: None identified in the instructions. 3. Capability inventory: File system read/write access limited to the project workspace; research delegation via the Agent tool. 4. Sanitization: No explicit sanitization or validation of ingested content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 03:27 AM
Security Audit — agent-trust-hub — compete