market-sizing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from external websites and search results, creating an attack surface for indirect prompt injection.
  • Ingestion points: The skill gathers industry reports, competitor data, and economic figures via WebSearch and WebFetch as outlined in references/research-sources.md.
  • Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions that might be embedded within the external research data.
  • Capability inventory: The skill has access to tools such as Bash, Write, Edit, and Glob as listed in the SKILL.md frontmatter, which could be misused if the agent follows malicious instructions hidden in a fetched web page.
  • Sanitization: There is no mention of sanitizing or validating the content retrieved from external URLs before it is processed or used to generate the final analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — market-sizing