competitive-deep-dive
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from competitor websites, help centers, release notes, and customer communities (SKILL.md, Step 4-8). This external content is analyzed in the same context as sensitive internal information.
- Ingestion points: Competitor primary sources, third-party evidence, and community/social sentiment signals as defined in
SKILL.mdandreferences/CONTEXT.md. - Boundary markers: The skill provides an 'Evidence and reasoning rules' framework (references/TRUST.md) and 'Context Acquisition Protocol' (references/CONTEXT.md) that instruct the agent to distinguish between observed facts and interpretations, and to cite sources.
- Capability inventory: The skill utilizes a set of LMTY-specific platform tools (e.g.,
get_report,get_competitor,get_evidence) to retrieve market and internal data. It lacks capabilities for arbitrary shell execution or writing to the local file system outside of producing the markdown artifact. - Sanitization: No automated sanitization or filtering of external input is described; the skill relies on the agent following instructional guardrails to identify and separate external claims from company facts.
- [DATA_EXPOSURE]: The skill accesses and summarizes highly sensitive internal business information, including call intelligence transcripts, CRM opportunity data (stage, value, loss reasons), and win/loss research (references/INTERNAL.md). While the skill includes privacy guidelines ('Access is not permission to expose'), the core function involves the aggregation of this sensitive internal data.
Audit Metadata