company-intel

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing content from untrusted external sources, which is a known attack vector for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent's context through web search results, investor materials, job boards (LinkedIn, Indeed), and employee reviews (Glassdoor) as specified in the 'Research Lenses' and 'Research Expectations' sections of SKILL.md.
  • Boundary markers: While the skill uses a structured output format and an evidence-labeling protocol (Fact, Inference, Assumption), it lacks explicit boundary markers or 'ignore' instructions for the external content it processes.
  • Capability inventory: The skill utilizes web search tools to gather information and produces detailed markdown documents as its primary output.
  • Sanitization: The instructions explicitly direct the agent not to sanitize public criticism or 'roadmap chaos' to maintain research objectivity, which inherently maintains the surface area for adversarial instructions embedded in that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:56 PM
Security Audit — agent-trust-hub — company-intel