competitor-tracking
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a bash script example designed for user execution to automate metadata retrieval using curl and jq from the Appeeky API.
- [EXTERNAL_DOWNLOADS]: The skill defines network operations to api.appeeky.com for fetching app metadata, keyword rankings, and user-generated reviews.
- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted user-generated content from app reviews. • Ingestion points: Data retrieved from api.appeeky.com (specifically app reviews and descriptions). • Boundary markers: Absent in the reporting instructions. • Capability inventory: Data summarization and report generation. • Sanitization: No validation or filtering of external content is specified.
Audit Metadata