skills/simota/agent-skills/compete/Gen Agent Trust Hub

compete

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) due to its core functionality of gathering and processing data from external, untrusted web sources.
  • Ingestion points: The skill is designed to fetch and analyze competitor websites, changelogs, review platforms, and OSINT sources using WebSearch and WebFetch tools as described in SKILL.md and the references/ directory.
  • Boundary markers: There are no explicit instructions within the prompt guidelines to use data delimiters or specific 'ignore' directives for the content retrieved from these external sources.
  • Capability inventory: The skill's capabilities are strictly limited to information research and strategic synthesis; it is explicitly forbidden from writing implementation code or performing actions beyond research synthesis.
  • Sanitization: No specific sanitization, validation, or filtering of the ingested web content is defined in the instructions before it is processed by the agent.
  • [SAFE]: No other malicious patterns, such as hardcoded credentials, remote code execution, or persistence mechanisms, were detected. The skill does not include any executable scripts or binary files, and its behavior is consistent with its stated purpose of strategic competitive analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 01:02 AM
Security Audit — agent-trust-hub — compete