competitive-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
ls) to inspect the user's local skill directories (e.g.,~/.claude/skills/). This diagnostic is used to identify missing recommended tools from the author's suite. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of additional tools using the
npx skills addcommand. This pattern involves fetching and executing code from the author's public repository. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing untrusted market data.
- Ingestion points: Instructions in
SKILL.mdandreferences/market-landscape.mddirect the agent to ingest external content from 'G2/Capterra reviews', 'LinkedIn job postings', and 'competitor marketing copy'. - Boundary markers: The prompt instructions do not provide explicit delimiters or instructions to the agent to ignore embedded commands within the analyzed data.
- Capability inventory: The agent has the ability to execute shell commands (
ls) and trigger package installations (npx), which could be abused if the agent is manipulated by data-embedded instructions. - Sanitization: There is no requirement or logic provided to sanitize or escape the external content before it is interpolated into the agent's context.
Audit Metadata