researching-latent-demand
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious code or direct security threats were detected. The skill is entirely instructional and provides a methodology for market research.
- [PROMPT_INJECTION]: The skill identifies a potential attack surface for indirect prompt injection by encouraging the agent to research data from external sources like Reddit, Hacker News, and GitHub issues. An attacker could theoretically place instructions in these public forums to influence the agent's research results or its actions when filing issues.
- Ingestion points: External research via web and GitHub tools (SKILL.md)
- Boundary markers: None specified in the instructions to separate untrusted data
- Capability inventory: Ability to file GitHub issues (SKILL.md)
- Sanitization: No explicit data sanitization or validation logic is requested in the skill
Audit Metadata