pricing-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local utility script scripts/check-output.py which validates the content and formatting of the pricing deliverable through simple text-based keyword matching.\n- [PROMPT_INJECTION]: The skill is designed to analyze external market data, creating an indirect prompt injection surface.\n
  • Ingestion points: Competitive pricing details and customer reviews from third-party platforms (Phase 2).\n
  • Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters for external content.\n
  • Capability inventory: The included scripts are limited to basic file system read access for validation; no tools for network exfiltration, arbitrary command execution, or file writing are provided.\n
  • Sanitization: Absent; there are no instructions to sanitize or escape data retrieved from external sources.\n- [SAFE]: References the LeadMagic Company Search API as an optional resource for market validation, which is a legitimate vendor tool provided by the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 08:48 PM
Security Audit — agent-trust-hub — pricing-strategy