market-scanner
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill does not contain any malicious commands, shell scripts, or executable code. The YAML frontmatter and markdown content are limited to descriptive process documentation.
- [NO_CODE]: No scripts (.py, .js, .sh) or tool configurations were found. The skill is purely informational.
- [PROMPT_INJECTION]: The workflow describes ingesting untrusted data from external sources like Twitter/X, HN, and blogs (Category 8: Indirect Prompt Injection surface). While no code is present to execute these scans, the process involves processing data that could contain malicious instructions.
- Ingestion points: SKILL.md (Step 1: Scan Sources)
- Boundary markers: Absent from the documentation.
- Capability inventory: None; no tools or scripts are defined in this skill.
- Sanitization: No sanitization or validation methods are described.
Audit Metadata