competitors

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform research by ingesting data from external sources and local configuration files, which presents an attack surface for indirect instructions.
  • Ingestion points: The skill reads product marketing context from files like .agents/product-marketing.md and performs 'review mining' from external sites such as G2, Capterra, and TrustRadius.
  • Boundary markers: The instructions do not define specific delimiters or security headers to separate untrusted research data from the agent's primary instructions.
  • Capability inventory: The skill generates structured YAML data and markdown content for marketing pages.
  • Sanitization: There is no requirement for the agent to sanitize or validate the content retrieved from external competitor reviews or feedback sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:56 AM
Security Audit — agent-trust-hub — competitors