discover-competitive-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to research external websites, which acts as an attack surface for indirect prompt injection.
  • Ingestion points: Step 2 in SKILL.md ('Gather Intelligence') directs the agent to research competitor websites, pricing pages, and customer reviews from third-party platforms.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands in external data are provided.
  • Capability inventory: The skill utilizes the agent's web browsing and searching capabilities.
  • Sanitization: No specific data validation or sanitization instructions are included for external content.
  • [SAFE]: The skill contains no executable code, remote script executions, hardcoded credentials, or persistence mechanisms. All provided files are instructional text or templates consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:21 AM
Security Audit — agent-trust-hub — discover-competitive-analysis