competitor-profiling

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate competitive intelligence tasks and follows best practices for data management, such as saving raw scrape data to local folders for auditing.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration or credential harvesting was found. The skill retrieves public SEO metrics and scrapes website content based on user-provided URLs, persisting this data to the local competitor-profiles/ directory.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute arbitrary remote code or scripts. It uses a defined set of MCP tools (Firecrawl and DataForSEO) for information gathering.
  • [PROMPT_INJECTION]: No direct prompt injection or behavior override patterns were detected. The skill ingests untrusted data from external websites and review platforms, creating an indirect prompt injection surface. However, this risk is mitigated as the skill's capabilities are limited to data synthesis and local file writing, which aligns with its primary research purpose. Ingestion points: external websites and review sites (Firecrawl); Boundary markers: absent; Capability inventory: local file system writes and tool calls; Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 04:39 PM