competitive-teardown

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions provide examples for querying the official Apple iTunes Search API to gather competitor review data. This is a reference to a well-known and safe service.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted data from external sources like App Store reviews, social media, and job postings, which creates a surface for indirect prompt injection.
  • Ingestion points: Raw signals are gathered from various public websites and APIs as defined in the data collection workflow.
  • Boundary markers: The instructions do not specify the use of data delimiters or safety instructions to disregard prompts embedded within the gathered external content.
  • Capability inventory: The skill includes a local Python script for matrix building and several analysis templates but does not grant direct execution of external content.
  • Sanitization: No explicit logic for filtering or sanitizing external text data is provided in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:34 PM
Security Audit — agent-trust-hub — competitive-teardown