competitive-intelligence
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting data from untrusted external sources.\n
- Ingestion points: The skill performs web searches on competitor product pages, news, blogs, and review sites (G2, Capterra), and optionally pulls data from CRM tools, chat logs (Slack), and document repositories.\n
- Boundary markers: There are no specified delimiters or instructions provided to the agent to help it differentiate between legitimate data and malicious instructions embedded within the external content it researches.\n
- Capability inventory: The agent has access to web search tools, organizational data connectors, and the ability to write local HTML files (the battlecard artifact).\n
- Sanitization: The skill lacks instructions for sanitizing or escaping the retrieved content before it is rendered into the HTML artifact, which could potentially allow malicious scripts from external sites to be executed if the user opens the resulting file.
Audit Metadata