scout
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface area because it instructs the agent to gather and process content from external competitor websites.
- Ingestion points: Research activities involve visiting external competitor URLs and reading local project context files (
.acumen.md,.acumen/competitors.md). - Boundary markers: Absent; the instructions do not define delimiters or explicit warnings to the agent to treat external content as untrusted.
- Capability inventory: The skill is authorized to read and write to the project's local file system (specifically the
.acumendirectory). - Sanitization: Absent; the skill does not require validation or sanitization of data retrieved from external sources before it is incorporated into the competitor map.
Audit Metadata