porters-five-forces

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied industry descriptions to perform strategic analysis, creating a potential surface for indirect prompt injection.
  • Ingestion points: User responses to prompts for industry definitions and force scoring in SKILL.md.
  • Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded commands within user-provided data.
  • Capability inventory: The skill does not invoke any dangerous tools, such as network requests, file system modifications, or shell command execution.
  • Sanitization: No explicit input validation or sanitization is performed on user-provided industry data.
  • [EXTERNAL_DOWNLOADS]: The skill provides references to several external domains for research, validation, and documentation purposes.
  • Academic and Corporate Sources: The skill links to Harvard Business Review (hbr.org), NYU Stern (stern.nyu.edu), Stanford University (stanford.edu), and Nvidia (nvidia.com). These are well-known and reputable entities used for providing empirical context.
  • Vendor Resources: The skill contains links to the author's official domain (deciqai.com) and GitHub repository (github.com/deciqAI), which are standard resources for documentation and updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — porters-five-forces