trend-scout

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several bundled shell scripts (generate-project-slug.sh, update-industry-metadata.sh, finalize-candidates.sh, prepare-phase3-data.sh) to manage project initialization, metadata updates, and data formatting. These scripts use standard tools like jq and python3 for local processing.
  • [EXTERNAL_DOWNLOADS]: Research is conducted via authorized search tools and numerous reputable external APIs, including OpenAlex, Semantic Scholar, arXiv, PubMed, USPTO, Lens.org, EPO OPS, EUR-Lex, SEC EDGAR, and FDA Open Data. These are well-known technology and academic services used for their intended purpose.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. Research data and configuration files are stored locally within the project's directory structure in the user's workspace.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web and API sources to generate trend candidates. While this represents a data ingestion surface, the risk is mitigated by the specialized nature of the subagents used (e.g., trend-web-researcher) and the inclusion of a dedicated candidate review phase (Phase 2.5) to verify signal quality and distinctiveness.
  • [SAFE]: The skill demonstrates safe operational practices, including configuration disclosure to the user before research begins, the use of semantic project identifiers, and robust logging of its internal phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — trend-scout