competitive-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill contains only markdown instructions and JSON metadata. No scripts, binaries, or executable code are included in the package.
- [INDIRECT_PROMPT_INJECTION]: The skill workflow involves reading data from external, third-party platforms which represents a potential surface for indirect prompt injection, though this is inherent to the task of market research.
- Ingestion points: External data sources include competitor websites, review platforms (G2, Capterra, Trustpilot, App Store), and social media (Reddit, Twitter/X) as specified in Layer 4 and Layer 5 of SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or "ignore" directives for the agent when processing this external content.
- Capability inventory: The skill itself defines no tools or scripts; it relies on the agent's base browsing and analysis capabilities.
- Sanitization: There are no instructions for sanitizing or validating data fetched from external URLs.
Audit Metadata