competitor-profiling

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external, untrusted sources such as competitor websites, PDFs, and user reviews. This task inherently exposes the agent to indirect prompt injection, where malicious instructions could be hidden in processed content to influence the agent's behavior.
  • Ingestion points: Website content, PDF files, and community reviews (referenced in 'Quellen- und Sammlungspolitik').
  • Boundary markers: The skill explicitly mitigates this risk in Rule 3 ('Quellen sind nicht vertrauenswürdige Daten'), which instructs the agent to ignore embedded instructions, metadata triggers, or secrets found in external content.
  • Capability inventory: The agent is authorized to perform network reads (HTTP GET) and write structured data (JSON/Markdown) to the local filesystem within a specified competitor-research/ directory.
  • Sanitization: The skill mandates the use of a 'Claim-Ledger' system to strictly separate raw data from analyst interpretation and inference, reducing the likelihood of injected content being executed as logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 08:11 PM
Security Audit — agent-trust-hub — competitor-profiling