find-niche

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and configuration files providing business analysis guidance. No executable code, scripts, or dangerous commands are present.
  • [CREDENTIALS_UNSAFE]: The skill includes documentation in references/03-monetization.md that explicitly advises users to keep SDK keys and secrets in secure environment stores rather than hardcoding them, following industry best practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing external data such as app reviews and competitor claims. However, it specifically instructs the agent in references/04-discovery-listing.md to treat these as untrusted inputs until corroborated, which acts as a proactive mitigation against indirect injection attacks.
  • [DATA_EXFILTRATION]: There are no network operations or sensitive data access commands. The skill guidelines explicitly warn against automated submission or publication without fresh owner confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:17 PM
Security Audit — agent-trust-hub — find-niche