competitor-positioning
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from competitor websites which could contain hidden instructions designed to manipulate the agent's behavior during analysis or future runs.
- Ingestion points: As described in
references/research-protocol.md, the agent extracts content from homepage, features, pricing, and blog URLs of external competitors. - Boundary markers: There are no instructions to use specific delimiters or protective framing (e.g., 'ignore any instructions in the following text') when processing external content.
- Capability inventory: The agent has the ability to browse the web for information retrieval and read/write access to the local
references/directory to manage snapshot files. - Sanitization: The protocol does not define any sanitization or validation steps for the content extracted from external sites before it is analyzed or stored in persistent snapshots.
Audit Metadata