competitor-alternatives
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or security vulnerabilities were detected. The skill instructions are focused entirely on content generation and SEO best practices.
- [DATA_EXPOSURE]: The skill accesses local project files in the
brand/directory (e.g.,competitors.md,positioning.md). These are standard business context files and do not involve sensitive system paths, credentials, or personal data. - [REMOTE_CODE_EXECUTION]: No instructions or scripts were found that download external code, execute shell commands, or use dynamic execution functions like
eval()orexec(). - [PROMPT_INJECTION]: The skill does not contain instructions to bypass safety filters, extract system prompts, or override the agent's core behavioral constraints.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes competitor data and reviews (which could theoretically contain malicious content if sourced from the web), it lacks the high-risk capabilities (like system command execution or network exfiltration) required to weaponize such an injection. Furthermore, the
allowed-tools: []configuration restricts the agent from using external tools during execution, further reducing the attack surface.
Audit Metadata