competitor-teardown
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
infshcommand-line utility to run various specialized applications for market research and data processing. - [EXTERNAL_DOWNLOADS]: References installation instructions and additional skill modules from the author's official GitHub repository.
- [REMOTE_CODE_EXECUTION]: Uses a Python execution tool to generate positioning map visualizations from static script templates included in the instructions.
- [PROMPT_INJECTION]: The skill processes untrusted data from external websites via search assistants and extraction tools, which represents an indirect prompt injection surface. This is expected behavior for research-oriented capabilities. [Ingestion points]: Search assistant results and website data extraction (SKILL.md). [Boundary markers]: None present in the example command templates. [Capability inventory]: Python execution for plotting, browser automation for screenshots, and image manipulation (SKILL.md). [Sanitization]: No sanitization logic was detected in the provided templates.
Audit Metadata