competitive-analysis-process
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from external, potentially attacker-controlled sources, creating a risk that malicious instructions embedded in that data could influence the agent's output.\n
- Ingestion points: The process explicitly directs the agent to gather data from external sources in Step 3 (buyer reviews via
voice-of-customer-miner) and Step 6 (patents, hiring surges, and news viaintelligence-collection-disciplines), as documented inSKILL.md.\n - Boundary markers: The instructions mandate the use of the
autonomous-investigationprotocol, which includes labeling data as Fact, Inference, or Assumption and using 'confidence stacking' to verify signals, providing a conceptual boundary for external content.\n - Capability inventory: The skill produces high-value artifacts including battle cards, positioning statements, and threat assessments, which are generated based on the aggregated external intelligence.\n
- Sanitization: While the skill emphasizes source-bias identification and multi-signal verification, it does not explicitly describe technical sanitization of the input data.
Audit Metadata