skills/tonone-ai/tonone/crest-compete/Gen Agent Trust Hub

crest-compete

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from the web, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Uses WebSearch and WebFetch to gather information about competitors and market landscapes from third-party websites.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its instructions and the data fetched from the web.
  • Capability inventory: The skill has access to potentially impactful tools such as Bash, Write, and Edit as specified in the allowed-tools section.
  • Sanitization: The instructions do not define any sanitization or validation steps for content retrieved from external sources before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill lists Bash in its allowed tools, but the instructions focus on analytical tasks rather than arbitrary command execution. This is consistent with the intended purpose of generating reports and managing files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — crest-compete