competitive-pricing-packaging-review
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, including competitor websites and public documentation, creating a potential surface for indirect prompt injection. \n
- Ingestion points: External data is collected via web research and market intelligence tools (referenced in
SKILL.mdandreferences/CONTEXT.md). \n - Boundary markers: The skill includes robust instructions in
references/TRUST.mdandreferences/INTERNAL.mdrequiring the agent to distinguish between observed facts, interpretations, and implications, and to attribute information to specific sources. \n - Capability inventory: The skill uses read-only market intelligence tools (
list_products,get_report, etc.) and internal data connectors (CRM, call intelligence). \n - Sanitization: While no automated sanitization is specified, the skill's reasoning framework emphasizes validation and cross-referencing of sources to mitigate the impact of potentially malicious external content.
Audit Metadata