skills/simota/agent-skills/compete/Gen Agent Trust Hub

compete

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is primarily focused on researching and analyzing external data via WebSearch and WebFetch tools, creating an attack surface for indirect prompt injection.
  • Ingestion points: Untrusted content from pricing pages, changelogs, job postings, and community forums is ingested into the agent context for analysis.
  • Boundary markers: The skill refers to _common/WEB_FETCH_SAFETY.md for sanitization but does not define explicit delimiters in the local markdown files.
  • Capability inventory: Capabilities include subagent orchestration, strategic artifact generation, and network access for research.
  • Sanitization: SKILL.md mandates a prompt-injection check on every search result or fetch operation before the data is incorporated into reports.
  • [COMMAND_EXECUTION]: The skill references the use of standard developer tools such as git and gh (GitHub CLI) for intelligence gathering and profile auditing. These are legitimate capabilities within the scope of a technical research and branding tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — compete