competitive-messaging-audit
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions and supporting documentation define a legitimate workflow for product marketing analysis without any evidence of malicious intent or behavior.
- [DATA_EXPOSURE]: The skill provides instructions for accessing internal sources such as CRM data and call intelligence. However, it mandates the use of read-only platform tools, enforces a 'least privilege' approach by instructing the agent to retrieve only necessary data, and explicitly warns against exposing sensitive personal or contract details in the final output.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (competitor copy, customer reviews), it lacks dangerous capabilities—such as arbitrary code execution or network writing to unauthorized domains—that would allow an indirect prompt injection to be exploited. The workflow is focused on reporting and analysis for human review.
- [COMMAND_EXECUTION]: No shell command execution or dynamic context injection patterns were found in the skill body or metadata.
- [OBFUSCATION]: Comprehensive scanning for Base64, zero-width characters, homoglyphs, and hidden text patterns yielded no results. The content is entirely transparent and human-readable.
Audit Metadata