company-intel
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing content from untrusted external sources, which is a known attack vector for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent's context through web search results, investor materials, job boards (LinkedIn, Indeed), and employee reviews (Glassdoor) as specified in the 'Research Lenses' and 'Research Expectations' sections of
SKILL.md. - Boundary markers: While the skill uses a structured output format and an evidence-labeling protocol (Fact, Inference, Assumption), it lacks explicit boundary markers or 'ignore' instructions for the external content it processes.
- Capability inventory: The skill utilizes web search tools to gather information and produces detailed markdown documents as its primary output.
- Sanitization: The instructions explicitly direct the agent not to sanitize public criticism or 'roadmap chaos' to maintain research objectivity, which inherently maintains the surface area for adversarial instructions embedded in that data.
Audit Metadata