positioning-with-ekram
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown-based instructions and reference documents. It contains no executable scripts (Python, Node.js, etc.) or binary files that could be used for malicious purposes.\n- [DATA_EXPOSURE]: The skill includes instructions to 'fetch the rival's homepage' for market analysis. This is a functional requirement for its purpose as a positioning advisor and does not involve accessing sensitive user directories (like .ssh or .aws) or exfiltrating private data.\n- [PROMPT_INJECTION]: The instructions focus on guiding the agent's reasoning process and persona (e.g., 'Position first. Brand second.'). While these are strong behavioral constraints, they do not attempt to bypass core safety filters or extract system-level prompts.\n- [EXTERNAL_DOWNLOADS]: The skill references external URLs for attribution and quotes (e.g., ekram.xyz). These are static informational links and do not involve the automated downloading or execution of remote payloads.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided copy and draft artifacts, which is a standard ingestion surface for text analysis tools. While it lacks explicit boundary markers for untrusted input, its limited capability scope (text generation and market research) minimizes the potential impact of such an attack.
Audit Metadata