competitor-tracker

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill appears to be a legitimate research tool that follows its stated purpose without hidden malicious instructions, obfuscation, or unauthorized access to sensitive data.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process untrusted data from external sources such as competitor blogs and forums (SKILL.md). While this is the core intended functionality, it creates a vector where adversarial content on a researched website could attempt to influence the agent's logic. The author includes mitigation instructions such as sourcing all claims, marking uncertain data, and maintaining objectivity to help the agent resist such influence.- [COMMAND_EXECUTION]: The skill instructs the agent to utilize local file system capabilities to save the final intelligence report as a Markdown file in the current working directory, which is a standard and safe operation for this type of task.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 07:32 PM
Security Audit — agent-trust-hub — competitor-tracker