anysite-market-research

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • Indirect Prompt Injection (MEDIUM): The skill's primary function is to process content from high-risk external sources including Reddit, Twitter, and general web scraping, which are prone to containing prompt injection payloads.
  • Ingestion Points: Data is ingested through search_reddit_posts, search_twitter_posts, search_linkedin_posts, parse_webpage, and duckduckgo_search (SKILL.md).
  • Boundary Markers: Absent. There are no delimiters or specific instructions provided to help the agent differentiate between research data and potential malicious instructions embedded within that data.
  • Capability Inventory: The skill provides tools for extensive network discovery and data retrieval via an MCP server, but lacks direct 'write' capabilities like file creation or command execution.
  • Sanitization: Absent. The agent is directed to synthesize findings directly from the ingested content without any validation or filtering steps.
  • Data Exposure & Exfiltration (LOW): The skill performs network operations to non-whitelisted external domains (Reddit, Twitter, LinkedIn, etc.) to fetch data. While consistent with its stated purpose, these tools provide a conduit for information flow to external parties.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:55 AM