competitor-content-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data (competitor blog posts, whitepapers) as indicated in the instructions (SKILL.md). There are no boundary markers or delimiters defined to separate user/competitor data from instructions, nor are there explicit commands for the agent to ignore instructions embedded within the analyzed content. While the skill does not define specific unsafe tools or scripts, the lack of data sanitization at the ingestion surface represents a vulnerability to indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — competitor-content-analyzer