competitor-profiling

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted content from external websites which could contain malicious instructions.
  • Ingestion points: Website content retrieved via firecrawl_scrape and firecrawl_crawl (SKILL.md).
  • Boundary markers: None identified in the synthesis instructions.
  • Capability inventory: File system writes to competitor-profiles/ and reading of local context files such as .agents/product-marketing.md (SKILL.md).
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known technology services (Firecrawl and DataForSEO) via MCP tools. This behavior is the primary intended purpose of the skill for competitive intelligence gathering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 05:45 AM
Security Audit — agent-trust-hub — competitor-profiling