competitive-dimensions-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions contain no evidence of jailbreak attempts, safety filter bypasses, or instructions to ignore previous system prompts. The instructional tone is standard and appropriate for the task.
- [DATA_EXFILTRATION]: No access to sensitive local file paths (e.g., SSH keys, AWS credentials, environment variables) was detected. The skill's network activity is limited to standard browser-based research for public competitor information.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any external package installations or execute remote scripts. There is no evidence of dynamic code execution (eval/exec) or runtime compilation.
- [OBFUSCATION]: The content is presented in clear, readable Markdown. No Base64, zero-width characters, homoglyphs, or other encoding techniques were used to hide malicious intent.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an inherent surface for indirect prompt injection because it ingests data from external sources (Step 2: Information Gathering). However, this is managed by the skill's low capability tier.
- Ingestion points: Step 2 in SKILL.md (official websites, help docs, social media, and third-party reports).
- Boundary markers: Absent; the skill does not explicitly instruct the agent to ignore embedded instructions in the research data.
- Capability inventory: High-level analysis, reporting, and matrix generation. No capabilities for file system modification, command execution, or sensitive credential access are granted or requested.
- Sanitization: Absent; the data is processed directly for analysis.
Audit Metadata