competitor-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by design, as it instructs the agent to fetch and analyze content from untrusted external sources.
  • Ingestion points: The research workflow explicitly involves fetching and extracting data from competitor websites (Step 1 and Step 4) and mining user reviews from third-party platforms like G2, Capterra, and Reddit.
  • Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings to help the agent distinguish between its operating playbook and potentially adversarial content retrieved from the web.
  • Capability inventory: The agent is instructed to read sensitive internal workspace context (e.g., strategy/brand.md, about/me.md) and is capable of writing generated drafts and reports to the filesystem (content/<platform>/drafts/).
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the external content before it is interpolated into the agent's context or processed for report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:07 PM
Security Audit — agent-trust-hub — competitor-analysis