competitor-content-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the public web, creating a potential surface for indirect prompt injection attacks where malicious instructions hidden in competitor content could influence agent behavior.
- Ingestion points: Data enters the agent context through search results and scraped markdown from external websites via tools like
exa_search,cloudsway_search, andcontext_dev_scrape_markdownas described inSKILL.md(Steps 3 and 4) andreferences/example-workflows.md. - Boundary markers: The instructions do not define explicit delimiters or "ignore embedded instructions" warnings to separate untrusted web content from the agent's core instructions.
- Capability inventory: The skill has access to web search, page extraction, and structured content analysis tools via the
sandbase_call_toolinterface. - Sanitization: There is no evidence of sanitization, filtering, or validation of the content extracted from external sources before it is processed by the agent.
Audit Metadata