competitive-intel

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the project's local file system (specifically the brand/ directory) and uses standard, non-malicious methods for competitive research.- [PROMPT_INJECTION]: No attempts to override system safety guidelines or extract system prompts were found. The 'Safety Rules' section explicitly reinforces data integrity and forbids fabrication or cross-project data contamination.- [DATA_EXFILTRATION]: No exfiltration patterns detected. The skill reads local brand files and writes to a specific competitors.md file within the user's workspace. It utilizes the external Exa MCP for web research, which is a standard tool for this purpose and not a hidden data leak vector.- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, shell commands, or package installations were identified. The skill focuses on natural language processing and information synthesis.- [OBFUSCATION]: Analysis of all text, including metadata and reference files, revealed no hidden characters, Base64 encoding of commands, or homoglyph substitutions.- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private file path access (like .ssh or .aws) were found. Recommendations for secret management (like .env files) were not present but also not violated.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:05 PM
Security Audit — agent-trust-hub — competitive-intel