competitive-executive-market-brief

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external competitive intelligence reports (LMTY) and internal corporate data (CRM records, call transcripts), creating a surface for indirect prompt injection.
  • Ingestion points: Market data and competitor signals are retrieved via tools described in references/LMTY.md and references/CONTEXT.md. Internal deal, customer, and product data are ingested through connectors described in references/INTERNAL.md.
  • Boundary markers: The skill instructions do not specify explicit boundary markers or unique delimiters to isolate untrusted external content from the prompt instructions.
  • Capability inventory: The skill is restricted to information synthesis and report generation; no subprocess execution, dynamic code evaluation, or direct network operations were identified in the skill's scripts or instructions.
  • Sanitization: The skill lacks programmatic sanitization of ingested text, relying instead on "epistemic model" guidelines in references/TRUST.md that instruct the agent to distinguish between observed facts and interpretations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:04 PM
Security Audit — agent-trust-hub — competitive-executive-market-brief