competitive-intelligence-radar

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install a plugin from a third-party GitHub repository (github.com/sabahudin-web/competitive-intelligence-radar). This external repository contains the bundled commands, agent definitions, and rules that execute within the agent environment.
  • [DATA_EXFILTRATION]: The skill manages sensitive business context, including domain names, tracked keywords, and competitor lists. It transmits this data to external services (BrightData for scraping and Notion for publishing) and requires API tokens for these services.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because its core functionality involves scraping live web data from competitor sites, news outlets, and social media. This untrusted content is processed by subagents and an analyst team to generate strategic recommendations.
  • Ingestion points: Competitor websites, news articles, and social sentiment data fetched via BrightData (SKILL.md, references/agent-roster.md).
  • Boundary markers: The instructions specify that findings should be cited and structured as JSON dossiers, but there are no explicit safety markers to prevent the agent from following instructions embedded in the scraped HTML or text.
  • Capability inventory: Writing to the local filesystem (outputs/ folder), modifying Notion databases, and managing multi-agent team sessions (references/command-reference.md).
  • Sanitization: No explicit sanitization or filtering of external web content is described prior to the analysis and debate phases.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 03:57 PM
Security Audit — agent-trust-hub — competitive-intelligence-radar