market-research

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external, untrusted sources such as Reddit, G2, and Capterra, which creates a potential surface for indirect prompt injection attacks.
  • Ingestion points: The skill ingests user arguments via $ARGUMENTS and retrieves content from external web platforms for competitor reviews and market data.
  • Boundary markers: The instructions do not define specific delimiters or instructions to treat external data as untrusted content.
  • Capability inventory: The agent's activities are limited to information gathering and summarization; no sensitive file system access, network exfiltration, or command execution tools are utilized.
  • Sanitization: There is no logic defined to sanitize or filter potentially malicious instructions embedded in the external content.
  • [NO_CODE]: The skill consists solely of a markdown file containing instructions and metadata, with no accompanying scripts, packages, or executable code included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:19 PM
Security Audit — agent-trust-hub — market-research