product-competitor-intelligence

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface\n
  • The skill facilitates extensive web research, creating a surface for indirect prompt injection where malicious instructions could be embedded in the content of competitor websites, retailer listings, or marketplaces processed by the agent.\n
  • Ingestion points: External data is retrieved from various websites and catalogs via search, crawl, and extract capabilities (SKILL.md).\n
  • Boundary markers: Absent. The skill does not provide instructions or delimiters to help the agent distinguish untrusted research data from its core system instructions.\n
  • Capability inventory: The agent leverages web searching, mapping, crawling, and data extraction to gather market intelligence and synthesize reports (SKILL.md).\n
  • Sanitization: Absent. There is no logic described for validating or sanitizing retrieved content before it is incorporated into the agent's context and final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 02:13 PM
Security Audit — agent-trust-hub — product-competitor-intelligence