competitor-profiling
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from external competitor websites and review platforms using scraping tools, creating a surface for indirect prompt injection.
- Ingestion points: Data enters the agent context from external URLs via
firecrawl_scrape,firecrawl_map, andfirecrawl_search. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the scraped content.
- Capability inventory: The skill can write files to the local filesystem and perform network requests via integrated tools.
- Sanitization: There is no mention of sanitizing or validating the external content before it is used to generate profile documents.
Audit Metadata