gtm-competitive-intel
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the web. Ingestion points: Untrusted data enters the agent context through the WebSearch tool and subagents scraping competitor websites, LinkedIn profiles, and review platforms such as G2 and Capterra. Boundary markers: The skill does not implement explicit delimiters or instructions to ignore embedded commands within the content retrieved from external sources. Capability inventory: The skill has the capability to read local project files, perform web searches, execute sub-tasks via the Task tool, and write dossiers to the local filesystem. Sanitization: There is no evidence of sanitization or filtering of the web-retrieved data before it is analyzed by the language models.
Audit Metadata