competitor-intelligence-skill-founder

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill performs research using external, untrusted web data from platforms such as G2, Trustpilot, LinkedIn, and Twitter/X, which creates a surface for indirect prompt injection.\n
  • Ingestion points: Step 3 (Research Phase) in SKILL.md identifies multiple external web search targets.\n
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters for the ingested web data.\n
  • Capability inventory: The agent uses web search tools and reads local project files (FOUNDER_CONTEXT.md).\n
  • Sanitization: There is no evidence of specific sanitization or validation of the content retrieved from web searches.\n- [DATA_EXFILTRATION]: The skill is configured to read a file named FOUNDER_CONTEXT.md from the project root to inform its analysis. While intended for personalization, this presents a data exposure surface if the file contains sensitive information like internal API keys or PII, as the agent may include that data in its generated analysis report.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 11:25 PM
Security Audit — agent-trust-hub — competitor-intelligence-skill-founder