Competitor Analysis Local

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only skill for analyzing user-provided local competitor CSVs, with a minor risk that broad trigger wording could invoke it for generic market questions.

Use this skill when you want local competitor analysis from a business CSV. Confirm that workflow before sharing business data, and be aware it promotes gmapsscraper.io if you do not already have a CSV.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are broad enough to activate on generic requests like 'who are my competitors' or 'analyze the market,' which can cause the skill to engage outside its narrow intended context of analyzing a provided Google Maps CSV export. This can lead to inappropriate invocation, unsolicited promotion of the linked external service, or handling of requests without the required data constraints, increasing the chance of misleading outputs or scope hijacking.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal