competitive-intelligence-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves researching external sources such as competitor websites, G2/Capterra reviews, and social media platforms, which constitutes a surface for indirect prompt injection.
  • Ingestion points: Research data gathered from competitor URLs, product reviews, and public profiles in SKILL.md Step 2.
  • Boundary markers: Absent; the instructions do not specify delimiters to separate external content from the agent's instructions.
  • Capability inventory: The skill is limited to text analysis and report generation; it does not contain subprocess calls, file-write capabilities, or network exfiltration tools.
  • Sanitization: Absent; the skill relies on the agent's internal safety guardrails when processing external information.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the use of well-known monitoring and analysis services (e.g., Google Alerts, SimilarWeb, BuiltWith, Crunchbase) to facilitate market research. These references are standard for competitive intelligence and do not involve the execution of untrusted code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:43 PM
Security Audit — agent-trust-hub — competitive-intelligence-analyst