competitive-position

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate financial analysis by fetching data from the SEC company tickers JSON endpoint and XBRL companyfacts. These are official and trusted government data sources.
  • [SAFE]: Web search operations are used appropriately to gather industry reports and competitor information. There is no evidence of data exfiltration or access to sensitive local files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from web searches and industry reports. While this presents an attack surface for indirect prompt injection, the skill lacks dangerous capabilities such as arbitrary command execution, file system writes, or dynamic code evaluation. Consequently, the risk is negligible.
  • [SAFE]: The logic for resolving tickers and mapping industry structures follows standard financial research workflows without using obfuscation or hidden persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:26 AM
Security Audit — agent-trust-hub — competitive-position