growth
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources during competitor and market research, which could potentially contain malicious instructions.
- Ingestion points: Web scraping via Firecrawl in
references/competitor.mdand "signal mining" from external "watering-hole" sources inreferences/positioning.md. - Boundary markers: None explicitly defined in the procedures to separate external data from system instructions.
- Capability inventory: The skill has access to powerful tools including
bash,run_command,write_to_file, andreplace_file_contentas defined inSKILL.mdandagents/openai.yaml. - Sanitization: No specific sanitization or filtering logic is described for the ingested content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill utilizes
run_commandandbashtools to perform automated updates and monitoring tasks. - Evidence:
references/audit.mddefinesAUTO-REPAIRactions that trigger command execution to set deadlines or pull analytics data.references/competitor.mddescribes a monitoring cadence that synthesis market moves automatically. - Mitigation: The skill documentation includes sophisticated safety protocols for these automated "loops," such as mandatory human checkpoints for high-risk actions (send/spend/publish) and explicit kill-switches.
Audit Metadata