competitive-deep-dive

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from competitor websites, help centers, release notes, and customer communities (SKILL.md, Step 4-8). This external content is analyzed in the same context as sensitive internal information.
  • Ingestion points: Competitor primary sources, third-party evidence, and community/social sentiment signals as defined in SKILL.md and references/CONTEXT.md.
  • Boundary markers: The skill provides an 'Evidence and reasoning rules' framework (references/TRUST.md) and 'Context Acquisition Protocol' (references/CONTEXT.md) that instruct the agent to distinguish between observed facts and interpretations, and to cite sources.
  • Capability inventory: The skill utilizes a set of LMTY-specific platform tools (e.g., get_report, get_competitor, get_evidence) to retrieve market and internal data. It lacks capabilities for arbitrary shell execution or writing to the local file system outside of producing the markdown artifact.
  • Sanitization: No automated sanitization or filtering of external input is described; the skill relies on the agent following instructional guardrails to identify and separate external claims from company facts.
  • [DATA_EXPOSURE]: The skill accesses and summarizes highly sensitive internal business information, including call intelligence transcripts, CRM opportunity data (stage, value, loss reasons), and win/loss research (references/INTERNAL.md). While the skill includes privacy guidelines ('Access is not permission to expose'), the core function involves the aggregation of this sensitive internal data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:04 PM
Security Audit — agent-trust-hub — competitive-deep-dive