competitor-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by design, as it instructs the agent to fetch and analyze content from untrusted external sources.
- Ingestion points: The research workflow explicitly involves fetching and extracting data from competitor websites (Step 1 and Step 4) and mining user reviews from third-party platforms like G2, Capterra, and Reddit.
- Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings to help the agent distinguish between its operating playbook and potentially adversarial content retrieved from the web.
- Capability inventory: The agent is instructed to read sensitive internal workspace context (e.g.,
strategy/brand.md,about/me.md) and is capable of writing generated drafts and reports to the filesystem (content/<platform>/drafts/). - Sanitization: There are no instructions for sanitizing, escaping, or validating the external content before it is interpolated into the agent's context or processed for report generation.
Audit Metadata