competitor-analysis

Warn

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains deceptive metadata, claiming to be an 'official' skill authored by 'Browserbase', which contradicts the provided uploader identity ('sickn33'). This metadata poisoning can lead users to overestimate the skill's safety profile and legitimacy.
  • [COMMAND_EXECUTION]: The instructions direct the user to modify their agent's security configuration (e.g., ~/.claude/settings.json) to auto-approve a wide range of shell commands, including rm, sed, cat, and mkdir. Broadly disabling these security prompts reduces human oversight and allows the agent to modify or delete files without explicit confirmation.
  • [PROMPT_INJECTION]: The skill processes untrusted content fetched from external websites to generate research reports and battle cards. This creates an indirect prompt injection surface where adversarial content on a target website could attempt to influence the agent's synthesis or the behavior of spawned subagents.
  • [EXTERNAL_DOWNLOADS]: The skill depends on an external CLI tool ('browse') installed via npm and requires the use of an external service API (Browserbase). Users should verify the integrity of external tools and be aware of the data shared with third-party APIs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 05:38 PM
Security Audit — agent-trust-hub — competitor-analysis