crest-compete
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from the web, which creates a potential surface for indirect prompt injection.
- Ingestion points: Uses
WebSearchandWebFetchto gather information about competitors and market landscapes from third-party websites. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its instructions and the data fetched from the web.
- Capability inventory: The skill has access to potentially impactful tools such as
Bash,Write, andEditas specified in theallowed-toolssection. - Sanitization: The instructions do not define any sanitization or validation steps for content retrieved from external sources before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill lists
Bashin its allowed tools, but the instructions focus on analytical tasks rather than arbitrary command execution. This is consistent with the intended purpose of generating reports and managing files.
Audit Metadata