compete
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes WebSearch and WebFetch tools to ingest untrusted data from external websites, reviews, and job postings for competitive analysis. This creates a potential surface for indirect prompt injection. The skill mitigates this risk by requiring the agent to perform prompt-injection checks on all fetched content using a standardized safety protocol (_common/WEB_FETCH_SAFETY.md) and mandates that all findings must be backed by cited sources to prevent the unverified adoption of external instructions.
Audit Metadata