trend-scout
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several bundled shell scripts (
generate-project-slug.sh,update-industry-metadata.sh,finalize-candidates.sh,prepare-phase3-data.sh) to manage project initialization, metadata updates, and data formatting. These scripts use standard tools likejqandpython3for local processing. - [EXTERNAL_DOWNLOADS]: Research is conducted via authorized search tools and numerous reputable external APIs, including OpenAlex, Semantic Scholar, arXiv, PubMed, USPTO, Lens.org, EPO OPS, EUR-Lex, SEC EDGAR, and FDA Open Data. These are well-known technology and academic services used for their intended purpose.
- [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. Research data and configuration files are stored locally within the project's directory structure in the user's workspace.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web and API sources to generate trend candidates. While this represents a data ingestion surface, the risk is mitigated by the specialized nature of the subagents used (e.g.,
trend-web-researcher) and the inclusion of a dedicated candidate review phase (Phase 2.5) to verify signal quality and distinctiveness. - [SAFE]: The skill demonstrates safe operational practices, including configuration disclosure to the user before research begins, the use of semantic project identifiers, and robust logging of its internal phases.
Audit Metadata