competitor-finder
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external information which introduces a surface for indirect prompt injection. * Ingestion points: The agent is instructed to ask for website URLs and company descriptions in Step 1 of SKILL.md. * Boundary markers: There are no explicit delimiters or instructions to ignore potential commands embedded in the retrieved web content or descriptions. * Capability inventory: The skill relies on the agent's ability to browse or search for competitive data; it does not explicitly invoke dangerous system-level capabilities or custom scripts. * Sanitization: No input sanitization or validation logic is defined for the external content.
- [NO_CODE]: The skill consists entirely of instructional markdown and does not include any executable scripts, configuration files, or external dependencies.
Audit Metadata