li-steam-market-research

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external platforms, which introduces a surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted content is retrieved from Steam store pages, player reviews, developer websites, and social media accounts (TikTok, Instagram, YouTube, X, Discord) during the game research process (SKILL.md, references/single-game-case-study.md).
  • Boundary markers: The instructions direct the agent to separate verifiable facts from analysis in its prose, but lack technical delimiters to define clear boundaries for external data within the prompt context.
  • Capability inventory: The skill possesses capabilities to write data to local files in CSV, JSON, HTML, and PDF formats (SKILL.md).
  • Sanitization: There is no mention of sanitizing or filtering external text before it is embedded into the dual-language PDF reports generated for users.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:52 AM
Security Audit — agent-trust-hub — li-steam-market-research