competitor-content-intelligence

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the public web, creating a potential surface for indirect prompt injection attacks where malicious instructions hidden in competitor content could influence agent behavior.
  • Ingestion points: Data enters the agent context through search results and scraped markdown from external websites via tools like exa_search, cloudsway_search, and context_dev_scrape_markdown as described in SKILL.md (Steps 3 and 4) and references/example-workflows.md.
  • Boundary markers: The instructions do not define explicit delimiters or "ignore embedded instructions" warnings to separate untrusted web content from the agent's core instructions.
  • Capability inventory: The skill has access to web search, page extraction, and structured content analysis tools via the sandbase_call_tool interface.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content extracted from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:26 AM
Security Audit — agent-trust-hub — competitor-content-intelligence