reputation-competitors

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not contain any executable scripts, binaries, or configuration files that could introduce code-based vulnerabilities.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface (Category 8) because it instructs the agent to ingest and analyze customer reviews from external websites.
  • Ingestion points: Phase 3 involves collecting 10-15 recent reviews from competitor business profiles on platforms like Google and Yelp.
  • Boundary markers: The instructions lack explicit delimiters or "ignore instructions within data" directives to help the agent distinguish between review content and agent instructions.
  • Capability inventory: The skill's primary capability is writing a markdown report to the local file system (COMPETITOR-REPUTATION-[business].md). It does not have access to subprocess execution or network-based exfiltration tools.
  • Sanitization: There are no instructions provided to sanitize or filter the collected review text before it is processed or written to the output file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 11:39 PM
Security Audit — agent-trust-hub — reputation-competitors