competitor-profiling

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Vulnerability. The skill is designed to retrieve and process large amounts of untrusted content from the public web, creating a significant attack surface for indirect prompt injection attacks.
  • Ingestion points: The skill uses tools such as browser/markdown, reddit/posts/{id}/comments, and x/users/{id}/tweets (as described in SKILL.md Workflow Steps 2 and 4) to ingest external data into the agent context.
  • Boundary markers: The instructions do not specify the use of delimiters or clear boundaries to distinguish untrusted external content from system instructions, nor do they advise the agent to ignore instructions embedded in the retrieved data.
  • Capability inventory: The skill has the ability to read project-level files (like .agents/product-marketing.md) and utilizes a broad set of network-enabled tools to aggregate data.
  • Sanitization: There is no evidence of sanitization or filtering of the retrieved content before it is processed by the AI model.
  • [DATA_EXFILTRATION]: Network Operations to Arbitrary Domains. The skill facilitates network requests to non-whitelisted external domains based on user input.
  • Evidence: The skill instructions in SKILL.md (Workflow Step 2) direct the agent to use the browser/markdown tool on arbitrary competitor URLs to extract business information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — competitor-profiling