competitive-intelligence-skill

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill researches competitor information from untrusted external web sources and internal company tools, which is then used to generate an interactive HTML report.
  • Ingestion points: Processes content from competitor websites, product updates, and review platforms (G2, Capterra, TrustRadius) as defined in Phase 3 and Phase 4 of the execution flow.
  • Boundary markers: Absent. The instructions do not specify any delimiters or safety warnings for the agent when processing retrieved data to prevent obedience to embedded instructions.
  • Capability inventory: The skill is designed to generate and save a local HTML file containing JavaScript and CSS based on the gathered data.
  • Sanitization: Absent. There are no explicit instructions for the agent to sanitize or escape data retrieved from external sources before interpolating it into the HTML and JavaScript structure of the generated battlecard.
  • [EXTERNAL_DOWNLOADS]: Initiates multiple web searches and data retrieval operations from various third-party domains, including competitor sites and product review platforms, to collect market intelligence.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:32 AM
Security Audit — agent-trust-hub — competitive-intelligence-skill