li-steam-market-research
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external platforms, which introduces a surface for indirect prompt injection attacks.
- Ingestion points: Untrusted content is retrieved from Steam store pages, player reviews, developer websites, and social media accounts (TikTok, Instagram, YouTube, X, Discord) during the game research process (
SKILL.md,references/single-game-case-study.md). - Boundary markers: The instructions direct the agent to separate verifiable facts from analysis in its prose, but lack technical delimiters to define clear boundaries for external data within the prompt context.
- Capability inventory: The skill possesses capabilities to write data to local files in CSV, JSON, HTML, and PDF formats (
SKILL.md). - Sanitization: There is no mention of sanitizing or filtering external text before it is embedded into the dual-language PDF reports generated for users.
Audit Metadata