product-trend-researcher

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: This skill consists entirely of markdown documentation and role-playing instructions. It does not include any scripts, binaries, or configuration files that execute code directly.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its reliance on external data sources.
  • Ingestion points: The skill is configured to use WebSearch and WebFetch tools to ingest data from the open web (as defined in the metadata).
  • Boundary markers: None. There are no instructions or delimiters provided to help the agent distinguish between its own system instructions and potentially malicious instructions embedded in fetched web content.
  • Capability inventory: The agent has Write and Edit permissions, which could be exploited to persist malicious instructions or data into local files if the agent is manipulated by external content.
  • Sanitization: There are no instructions for validating, filtering, or sanitizing the content retrieved from external sources before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 09:44 AM
Security Audit — agent-trust-hub — product-trend-researcher