competitive-analysis
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
SKILL.mdfile contains instructions for the agent to automatically execute directory listings (ls) on multiple paths, including hidden directories in the user's home folder (e.g.,~/.claude/skills/,~/.agent/skills/) to detect companion skills upon activation.\n- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to recommend the installation of additional tools usingnpx skills add AbsolutelySkilled/AbsolutelySkilled, which involves downloading and executing code from the npm registry.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external, potentially untrusted market data and competitor reviews without sanitization.\n - Ingestion points: User-provided competitor data and external reviews referenced in
SKILL.md.\n - Boundary markers: Absent in the feature matrix and SWOT templates provided in the instructions.\n
- Capability inventory: The agent is instructed to execute shell commands (
ls) for autonomous companion checks inSKILL.md.\n - Sanitization: No sanitization or validation of the input data is mentioned or implemented in the workflow.
Audit Metadata