market-funnel
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content from user-provided URLs via the
/market funnel <url>command, which is an indirect prompt injection surface. - Ingestion points: External website content from the user-provided URL is read by the agent (SKILL.md).
- Boundary markers: Absent; there are no instructions to the agent to delimit or ignore instructions found within the fetched URL content.
- Capability inventory: The skill's functionality is limited to generating a markdown report (
FUNNEL-ANALYSIS.md). No capabilities for network requests, file system modification, or subprocess execution are present in the skill definition. - Sanitization: No validation or sanitization of the external content is requested.
- [SAFE]: The skill contains no executable scripts, obfuscated content, or unauthorized network operations. Its behavior is consistent with its stated purpose.
Audit Metadata