competitor-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and analyzes content from external websites, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill uses WebFetch in Step 2 to retrieve content from the homepages and key pages of competitors identified in the search phase.
  • Boundary markers: The instructions do not specify boundary markers or provide the agent with explicit guidance to ignore instructions that might be embedded in the fetched web content.
  • Capability inventory: The skill is configured with access to the Bash, Read, Write, WebFetch, and WebSearch tools, providing a surface for action if an injection were successful.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external URLs before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:39 PM