competitive-intelligence
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from external sources like competitor websites, reviews, and news during its research phases.
- Ingestion points: Data enters the agent context through web search results in Phase 2 and 3, and via internal connectors (CRM, Docs, Chat, Transcripts) in Phase 4.
- Boundary markers: The execution flow lacks explicit delimiters or instructions to ignore embedded commands within the retrieved research content.
- Capability inventory: The skill performs web searches, reads data from connected internal tools, and generates a self-contained HTML artifact.
- Sanitization: There is no mention of sanitizing or validating ingested content before it is interpolated into the final HTML report template, which could lead to malicious content being rendered in the artifact.
Audit Metadata