competitive-pricing-intel
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate data gathering of publicly accessible information from pricing pages and search results. No malicious instructions, obfuscation, or unauthorized network behaviors were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external content from competitor websites (Ingestion points: Phase 1A, 1B, and 1C in SKILL.md). While it lacks explicit boundary markers or sanitization, the risk is minimal because the agent is instructed to extract structured data into a comparison table, and it lacks high-risk capabilities like dynamic code execution (Capability inventory: fetch_webpage, web_search, file-write).
- [COMMAND_EXECUTION]: The documentation provides a sample bash command for scheduling a cron job. This is intended for user-directed automation and does not represent a vulnerability or automated command execution within the agent's internal skill logic.
Audit Metadata