competitive-launch-readiness
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and potentially untrusted data, such as competitor documentation and customer call transcripts, to generate launch assessments. While the skill includes detailed reasoning and evidence protocols (specifically in
references/TRUST.md), it does not implement explicit technical boundary markers or sanitization to prevent adversarial instructions within that data from potentially influencing the agent's behavior during processing. - Ingestion points: Competitor product documentation, customer transcripts, win/loss research, and user-provided PRDs/launch briefs (referenced in
SKILL.mdandreferences/CONTEXT.md). - Boundary markers: The skill lacks explicit string delimiters or unique markers to programmatically isolate ingested external data from its core instructions.
- Capability inventory: The skill's capabilities are restricted to specialized market intelligence tools (MCP); no dangerous system-level capabilities such as subprocess execution, file writing, or arbitrary network requests were identified.
- Sanitization: No explicit sanitization or filtering logic is defined for the external inputs before they are analyzed by the agent.
Audit Metadata