competitor-price-tracker
Pass
Audited by Gen Agent Trust Hub on Feb 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Prompt Injection] (SAFE): No direct prompt injection, jailbreak attempts, or instructions to bypass safety filters were detected in the skill markdown.- [Indirect Prompt Injection] (LOW): The skill is designed to have the agent monitor and analyze competitor pricing pages. This presents an indirect prompt injection surface where a third party could host malicious instructions on a website to manipulate the agent's output or recommendations. 1. Ingestion points: External competitor pricing pages and strategy documents. 2. Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore embedded commands in the source data. 3. Capability inventory: No internal scripts; the skill relies on the agent's inherent web-browsing and reasoning capabilities. 4. Sanitization: Absent; no validation or filtering steps are defined for the scraped content.- [No Code] (SAFE): The skill contains no scripts (.py, .js, .sh), executables, or package manifests, which significantly limits the potential for traditional malware, remote code execution, or persistence mechanisms.
Audit Metadata