competitive-white-space

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from competitor websites, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External website content (homepage, about, products, pricing, case studies) fetched during the research workflow in SKILL.md.
  • Boundary markers: None identified; the skill lacks explicit instructions to treat fetched content as untrusted data or to ignore embedded instructions.
  • Capability inventory: The agent is authorized to search the web, fetch external URLs, and write files in .docx and HTML formats.
  • Sanitization: No sanitization or validation logic is specified for the data retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:49 PM
Security Audit — agent-trust-hub — competitive-white-space