setup-competitors-md

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a legitimate workflow to document the competitive landscape of a project. It identifies competitors through repository analysis and web-based research tools.
  • [PROMPT_INJECTION]: The skill instructions do not contain patterns intended to bypass safety filters, override agent behavior, or extract internal system prompts.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer or hardcoded credentials was found. File access is limited to project documentation, and network activity is restricted to the research tools required for the task.
  • [REMOTE_CODE_EXECUTION]: The skill does not involve package installations or the execution of remote scripts from external servers.
  • [SAFE]: An analysis of the indirect prompt injection surface was performed. While the skill ingests data from external websites during research, the impact is low as the information is synthesized into a static markdown document. 1. Ingestion points: External URLs and web research tools (SKILL.md, Workflow Step 2). 2. Boundary markers: Absent. 3. Capability inventory: File system read/write and web research capabilities. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:40 PM
Security Audit — agent-trust-hub — setup-competitors-md