market-research
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve executing local scripts (
node scripts/run-state-check.jsandbash scripts/evidence-log.sh) to maintain the research state and log quotes to the repository root. These are intended functions for managing collected data. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external market research sources.
- Ingestion points: The agent is instructed to search for and capture quotes from external sources and URLs.
- Boundary markers: The instructions do not define specific delimiters for separating processed quotes from the system prompt.
- Capability inventory: The skill has the capability to run local shell scripts and node processes.
- Sanitization: No explicit sanitization or escaping mechanisms for the captured quotes are defined in the instructions.
Audit Metadata