competitive-teardown
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves gathering competitor information from external sources via web research. This introduces a risk where the agent could be influenced by instructions hidden in the processed data.
- Ingestion points: The skill ingests data from external websites (screenshots, walkthroughs, app store listings, or public design write-ups) in the first step of the workflow.
- Boundary markers: No explicit boundary markers or instructions to disregard embedded commands in the researched data are present to prevent the agent from obeying instructions found in external content.
- Capability inventory: The agent is authorized to perform scoped, reversible edits to the current Figma design file and generate recommendations based on the research findings.
- Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content gathered from the web before it is used to generate design recommendations or file edits.
Audit Metadata