competitor-alternatives
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill is composed entirely of markdown guidelines and templates. It contains no scripts (Python, Node.js, Shell) or binaries that could be executed on a system.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to research external sources like review websites (G2, Capterra, TrustRadius) and competitor sites.\n
- Ingestion points: External product review platforms and competitor websites as specified in the research process in references/detailed-guide.md.\n
- Boundary markers: None identified in the instructions for separating external content from the prompt.\n
- Capability inventory: No risky capabilities (file writing, shell access, or custom network operations) are defined in the skill files.\n
- Sanitization: No specific sanitization or validation steps are provided for handling data from external research sources.\n
- Risk Assessment: Given the lack of executable capabilities and the static nature of the intended output, this ingestion surface represents a safe instructional pattern.\n- [SAFE]: No malicious patterns such as credential harvesting, obfuscation, persistence mechanisms, or unauthorized privilege escalation were detected. The skill's content is consistent with its stated marketing purpose. Although the frontmatter contains a 'risk: critical' field, this is not supported by the skill's content and does not represent a functional security threat.
Audit Metadata