competitor-tracking

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a bash script example designed for user execution to automate metadata retrieval using curl and jq from the Appeeky API.
  • [EXTERNAL_DOWNLOADS]: The skill defines network operations to api.appeeky.com for fetching app metadata, keyword rankings, and user-generated reviews.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted user-generated content from app reviews. • Ingestion points: Data retrieved from api.appeeky.com (specifically app reviews and descriptions). • Boundary markers: Absent in the reporting instructions. • Capability inventory: Data summarization and report generation. • Sanitization: No validation or filtering of external content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:42 PM
Security Audit — agent-trust-hub — competitor-tracking