competitive-research-snapshot

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from external sources including competitor websites, product review pages, and news articles. This content could contain hidden instructions designed to manipulate the agent's output or behavior.
  • Ingestion points: Step 4 in SKILL.md identifies company sites, pricing pages, press releases, and analyst/review sites as data sources.
  • Boundary markers: The skill requires the use of Fact, Inference, and Assumption labels for all findings in the output schema defined in SKILL.md, providing a structured check against unverified content.
  • Capability inventory: The Key Concepts and Application sections in SKILL.md define capabilities for web search and content intelligence collection (OSINT/FININT/SIGINT).
  • Sanitization: The workflow in SKILL.md requires manual classification, source verification, and explicit citation for every claim, which serves as a mitigation strategy against direct adoption of malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:56 PM
Security Audit — agent-trust-hub — competitive-research-snapshot