competitive-landscape

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: A thorough analysis of the skill instructions found no evidence of malicious code, obfuscated commands, persistence mechanisms, or unauthorized data exfiltration. The tools and workflows described (keyword metrics, SERP results, domain overviews) are consistent with legitimate SEO market research functions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external search results, which is a common attack surface for indirect prompt injection.
  • Ingestion points: External data is retrieved via get_serp_results, research_keywords, and get_ranked_keywords as defined in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or specific markers to isolate external data from the agent's instruction context.
  • Capability inventory: The tools requested by this skill are limited to data retrieval; no capabilities for file writing, system command execution, or non-whitelisted network operations were identified in the provided file.
  • Sanitization: There is no mention of explicit sanitization or filtering logic for the data retrieved from search engines.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 01:14 PM
Security Audit — agent-trust-hub — competitive-landscape