competitor-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches and analyzes content from external websites, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The skill uses
WebFetchin Step 2 to retrieve content from the homepages and key pages of competitors identified in the search phase. - Boundary markers: The instructions do not specify boundary markers or provide the agent with explicit guidance to ignore instructions that might be embedded in the fetched web content.
- Capability inventory: The skill is configured with access to the
Bash,Read,Write,WebFetch, andWebSearchtools, providing a surface for action if an injection were successful. - Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external URLs before it is processed by the agent.
Audit Metadata