competitor-profiling

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's mandatory content standards explicitly prohibit hidden Unicode characters and require the replacement of em dashes. This is a security best practice that mitigates character-based obfuscation and homograph attacks in the agent's output.
  • [SAFE]: The skill references several well-known and trusted technology industry platforms for research, such as LinkedIn, G2, Semrush, Ahrefs, and Crunchbase. These are legitimate resources for the skill's stated purpose of competitive intelligence.
  • [PROMPT_INJECTION]: The skill requires the agent to research and process data from untrusted external sources (competitor websites, customer reviews, and job postings), which creates a surface for indirect prompt injection.
  • Ingestion points: Competitor URLs, product pages, and third-party review sites (G2, Capterra, etc.) as specified in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters to wrap external content or provide explicit warnings to the agent to ignore embedded instructions within that content.
  • Capability inventory: The skill is strictly focused on text synthesis and dossier creation within SKILL.md; it does not request access to shells, file system writes, or administrative tools.
  • Sanitization: There are no requirements for sanitizing or filtering the text gathered from external research sources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:03 AM
Security Audit — agent-trust-hub — competitor-profiling