competitor-profiling

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, which is a standard surface for indirect prompt injection attacks. \n
  • Ingestion points: External URLs, competitor websites, documentation, and community reviews are accessed and processed as evidence (referenced in SKILL.md and references/profile-workflow.md). \n
  • Boundary markers: The workflow instructions include separating raw evidence from conclusions and recording source metadata, providing structural separation, but lack explicit instructions to disregard potential commands within source materials. \n
  • Capability inventory: The skill uses agent capabilities to perform research, profile generation, and market comparison. \n
  • Sanitization: There are no explicit instructions to sanitize or validate the content retrieved from external sources before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:55 AM
Security Audit — agent-trust-hub — competitor-profiling