discover-competitive-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to research external websites, which acts as an attack surface for indirect prompt injection.
- Ingestion points: Step 2 in SKILL.md ('Gather Intelligence') directs the agent to research competitor websites, pricing pages, and customer reviews from third-party platforms.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands in external data are provided.
- Capability inventory: The skill utilizes the agent's web browsing and searching capabilities.
- Sanitization: No specific data validation or sanitization instructions are included for external content.
- [SAFE]: The skill contains no executable code, remote script executions, hardcoded credentials, or persistence mechanisms. All provided files are instructional text or templates consistent with the skill's stated purpose.
Audit Metadata