competitor-pages

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external competitor web pages provided via user arguments. This content is untrusted and could contain hidden instructions or malicious patterns intended to manipulate the agent's behavior during the analysis phase.
  • Ingestion points: Competitor URLs provided in the argument-hint.
  • Boundary markers: None defined in the skill entry point.
  • Capability inventory: The skill indicates it performs deep analysis of structure, content, and metadata, which requires fetching and parsing external data.
  • Sanitization: No specific sanitization or escaping of the fetched content is described in the prompt logic.
  • [COMMAND_EXECUTION]: The skill uses a directory traversal instruction (../../seo/competitor-pages/SKILL.md) to dynamically load its core instructions. This pattern redirects the agent's workflow to a file outside the immediate skill directory, which could be used to access unauthorized files if the environment is not properly sandboxed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:14 PM
Security Audit — agent-trust-hub — competitor-pages