market-research

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions involve executing local scripts (node scripts/run-state-check.js and bash scripts/evidence-log.sh) to maintain the research state and log quotes to the repository root. These are intended functions for managing collected data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external market research sources.
  • Ingestion points: The agent is instructed to search for and capture quotes from external sources and URLs.
  • Boundary markers: The instructions do not define specific delimiters for separating processed quotes from the system prompt.
  • Capability inventory: The skill has the capability to run local shell scripts and node processes.
  • Sanitization: No explicit sanitization or escaping mechanisms for the captured quotes are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 10:33 AM
Security Audit — agent-trust-hub — market-research