market-research
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external, untrusted sources such as Reddit, G2, and Capterra, which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: The skill ingests user arguments via $ARGUMENTS and retrieves content from external web platforms for competitor reviews and market data.
- Boundary markers: The instructions do not define specific delimiters or instructions to treat external data as untrusted content.
- Capability inventory: The agent's activities are limited to information gathering and summarization; no sensitive file system access, network exfiltration, or command execution tools are utilized.
- Sanitization: There is no logic defined to sanitize or filter potentially malicious instructions embedded in the external content.
- [NO_CODE]: The skill consists solely of a markdown file containing instructions and metadata, with no accompanying scripts, packages, or executable code included.
Audit Metadata