competitor-profiling
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted data from arbitrary competitor URLs.
- Ingestion points: The skill uses Firecrawl to scrape content (homepage, pricing, features, blog) from any URL provided by the user.
- Boundary markers: The instructions do not define clear delimiters or explicitly instruct the agent to ignore instructions embedded in the scraped markdown content during the synthesis phase.
- Capability inventory: The agent has the ability to write files to the project directory and perform network operations via tool calls.
- Sanitization: There are no instructions for sanitizing or escaping the content retrieved from external sites before it is incorporated into the synthesized markdown profiles.
- [EXTERNAL_DOWNLOADS]: The skill fetches data from external websites and interacts with third-party service providers (Firecrawl and DataForSEO) to gather competitive intelligence and SEO metrics.
- [DATA_EXFILTRATION]: The skill reads potentially sensitive internal information from context files such as
product-marketing.md. While this is intended to guide the research, the logic involves using this internal context to formulate queries and parameters for external API calls, which represents a potential flow of internal data to external services.
Audit Metadata