competitive-research-snapshot
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from external sources including competitor websites, product review pages, and news articles. This content could contain hidden instructions designed to manipulate the agent's output or behavior.
- Ingestion points: Step 4 in
SKILL.mdidentifies company sites, pricing pages, press releases, and analyst/review sites as data sources. - Boundary markers: The skill requires the use of
Fact,Inference, andAssumptionlabels for all findings in the output schema defined inSKILL.md, providing a structured check against unverified content. - Capability inventory: The
Key ConceptsandApplicationsections inSKILL.mddefine capabilities for web search and content intelligence collection (OSINT/FININT/SIGINT). - Sanitization: The workflow in
SKILL.mdrequires manual classification, source verification, and explicit citation for every claim, which serves as a mitigation strategy against direct adoption of malicious instructions.
Audit Metadata