amazon-competitor-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external Amazon listings and web search results, which could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Step 1 (Competitive Data Collection) in SKILL.md explicitly gathers product specifications and reviews from external web sources.
  • Boundary markers: The skill documentation does not specify the use of delimiters or 'ignore instructions' directives for handling this external content.
  • Capability inventory: The skill documentation focuses on analysis and summarization; it does not explicitly define or request high-risk capabilities like local file system writes or arbitrary shell command execution.
  • Sanitization: There is no mention of sanitization or filtering logic applied to the external data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:20 PM
Security Audit — agent-trust-hub — amazon-competitor-analysis