competitive-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file contains instructions for the agent to automatically execute directory listings (ls) on multiple paths, including hidden directories in the user's home folder (e.g., ~/.claude/skills/, ~/.agent/skills/) to detect companion skills upon activation.\n- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to recommend the installation of additional tools using npx skills add AbsolutelySkilled/AbsolutelySkilled, which involves downloading and executing code from the npm registry.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external, potentially untrusted market data and competitor reviews without sanitization.\n
  • Ingestion points: User-provided competitor data and external reviews referenced in SKILL.md.\n
  • Boundary markers: Absent in the feature matrix and SWOT templates provided in the instructions.\n
  • Capability inventory: The agent is instructed to execute shell commands (ls) for autonomous companion checks in SKILL.md.\n
  • Sanitization: No sanitization or validation of the input data is mentioned or implemented in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — competitive-analysis