competitor-teardown

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the belt-sh/cli and additional utility skills for web searching and prompt engineering.
  • [COMMAND_EXECUTION]: Utilizes a dedicated CLI tool, restricted via the allowed-tools frontmatter to the belt command, to run modular research applications for competitive intelligence.
  • [REMOTE_CODE_EXECUTION]: Includes a Python template for generating positioning maps using the matplotlib library, which is executed through a specialized execution tool.
  • [PROMPT_INJECTION]: The skill ingests data from external web searches and site content, which constitutes an ingestion point for potentially untrusted third-party data (indirect prompt injection).
  • Ingestion points: tavily/search-assistant, exa/search, and infsh/agent-browser.
  • Boundary markers: Absent in the provided command examples.
  • Capability inventory: Ability to run Python code and perform network requests via the belt toolset.
  • Sanitization: No explicit sanitization or filtering of external content is described before data is processed for reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — competitor-teardown