idea-comparison

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is designed to autonomously ingest and process untrusted data from external web searches and user-provided idea descriptions.
  • Ingestion points: The agent performs web searches for competitors, pricing signals, and market trends, and also takes business idea descriptions directly from user input (SKILL.md, Step 1).
  • Boundary markers: The instructions do not define clear delimiters (e.g., XML tags or triple quotes) to separate untrusted search results from the system instructions, increasing the risk that embedded instructions in search snippets could influence the agent's behavior.
  • Capability inventory: The skill utilizes autonomous search tools and reads local markdown files (.claude/skills/_shared/philosophy.md) to inform its scoring logic.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the content retrieved from external research before it is interpolated into the analysis flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 12:36 AM
Security Audit — agent-trust-hub — idea-comparison