market-finder
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources, which could potentially contain malicious instructions intended to influence agent behavior.
- Ingestion points: The skill ingests untrusted data from external web searches (Google Maps, Yelp, G2, Crunchbase, etc.) as described in 'references/vertical-presets.md', and from user-provided files or inline text (CSV, Google Sheets) as described in 'references/audit-mode.md'.
- Boundary markers: The instructions lack specific guidance on using strong boundary markers or delimiters to strictly separate untrusted data from instructions during the deduplication, scoring, and auditing phases.
- Capability inventory: The skill utilizes tool capabilities for performing extensive web searches and reading/writing structured data to the local workspace.
- Sanitization: While the skill performs data normalization (stripping protocols, non-digits, and punctuation), this is primarily for data matching and does not include specific filtering for potential prompt injection patterns.
Audit Metadata