startup-pricing-lab

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources such as competitor pricing pages, repositories, and landing pages.
  • Ingestion points: SKILL.md (Step 1) directs the agent to research external URLs and landing pages to build a product profile.
  • Boundary markers: The skill does not provide specific delimiters or instructions to ignore embedded commands within the research material.
  • Capability inventory: The agent has the capability to execute bundled shell commands (Step 6 and 8) to run scoring and reporting scripts, and it writes multiple files to the local workspace.
  • Sanitization: There is no explicit sanitization step for external text before it is summarized and converted into the analysis schema, creating a potential surface for indirect instructions to influence the agent's report output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 03:11 PM
Security Audit — agent-trust-hub — startup-pricing-lab