skyscraper-technique

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's configuration specifies a dependency on the Node.js package @clawfu/mcp-skills as the designated MCP server.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves retrieving and analyzing external competitor content and URLs provided by the user, which presents an attack surface for instructions hidden in third-party content.
  • Ingestion points: The skill instructions prompt the agent to "Analyze this competitor's content" and "Find linkable assets" from URLs provided by the user (SKILL.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined in the methodology.
  • Capability inventory: The skill is capable of generating outreach emails, creating content plans, and performing competitive analysis based on the ingested data.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the external content before processing it into the outreach templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:25 PM
Security Audit — agent-trust-hub — skyscraper-technique