competitor-price-tracker

Pass

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Prompt Injection] (SAFE): No direct prompt injection, jailbreak attempts, or instructions to bypass safety filters were detected in the skill markdown.- [Indirect Prompt Injection] (LOW): The skill is designed to have the agent monitor and analyze competitor pricing pages. This presents an indirect prompt injection surface where a third party could host malicious instructions on a website to manipulate the agent's output or recommendations. 1. Ingestion points: External competitor pricing pages and strategy documents. 2. Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore embedded commands in the source data. 3. Capability inventory: No internal scripts; the skill relies on the agent's inherent web-browsing and reasoning capabilities. 4. Sanitization: Absent; no validation or filtering steps are defined for the scraped content.- [No Code] (SAFE): The skill contains no scripts (.py, .js, .sh), executables, or package manifests, which significantly limits the potential for traditional malware, remote code execution, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 18, 2026, 03:24 AM