market-intel-brief

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: All identified external resources, including the domain uniqueclub.ai and the GitHub repository wulaosiji/founder-skills, are directly associated with the skill's author and represent legitimate vendor resources.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is instructed to search for and ingest untrusted data from external AI industry news sources and competitor announcements.
  • Ingestion points: External news content, competitive updates, and funding data fetched during the 'Intelligence Gathering' step in SKILL.md.
  • Boundary markers: The skill uses a highly structured Markdown template to delimit gathered information, which helps separate external content from agent instructions.
  • Capability inventory: The skill has the capability to write local files (Market_Brief.md) and perform network-write operations to publishing platforms like Feishu or via Email.
  • Sanitization: There are no explicit instructions for sanitizing or escaping the fetched content before interpolation into the brief.
  • [EXTERNAL_DOWNLOADS]: The skill performs standard information retrieval by searching for industry intelligence. These operations are essential to the skill's core function and do not involve executing untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 07:32 PM
Security Audit — agent-trust-hub — market-intel-brief