competitor-finder

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external information which introduces a surface for indirect prompt injection. * Ingestion points: The agent is instructed to ask for website URLs and company descriptions in Step 1 of SKILL.md. * Boundary markers: There are no explicit delimiters or instructions to ignore potential commands embedded in the retrieved web content or descriptions. * Capability inventory: The skill relies on the agent's ability to browse or search for competitive data; it does not explicitly invoke dangerous system-level capabilities or custom scripts. * Sanitization: No input sanitization or validation logic is defined for the external content.
  • [NO_CODE]: The skill consists entirely of instructional markdown and does not include any executable scripts, configuration files, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:21 PM
Security Audit — agent-trust-hub — competitor-finder