market-funnel

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes content from user-provided URLs via the /market funnel <url> command, which is an indirect prompt injection surface.
  • Ingestion points: External website content from the user-provided URL is read by the agent (SKILL.md).
  • Boundary markers: Absent; there are no instructions to the agent to delimit or ignore instructions found within the fetched URL content.
  • Capability inventory: The skill's functionality is limited to generating a markdown report (FUNNEL-ANALYSIS.md). No capabilities for network requests, file system modification, or subprocess execution are present in the skill definition.
  • Sanitization: No validation or sanitization of the external content is requested.
  • [SAFE]: The skill contains no executable scripts, obfuscated content, or unauthorized network operations. Its behavior is consistent with its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 01:06 PM
Security Audit — agent-trust-hub — market-funnel