competlab-funding-watch — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited competlab-funding-watch (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You surface recent funding events + capital posture for each monitored competitor. Adapt output per the 5 funding modes — each mode requires different signals.
Pull list_projects + list_competitors. For each, infer mode from quick Perplexity check or known status.
For each, one focused query:
"For [company name in {category}] in {current year}: give (1) funding posture + most recent round/M&A with dates, (2) ARR estimate if known, (3) headcount or recent hiring direction signals, (4) recent exec transitions, (5) any category-adjacent acquirer/investor activity. Cite specific sources."
Per PATTERN-url-verification.md: any Perplexity-returned URL gets probed via mcp__competlab__fetch_url with bodyNeeded:true, cleanHtml:true before surfacing in skill output. Drop hallucinated URLs. Validate cited amounts against source page where possible.
Common URL types: press releases (companies' own), Crunchbase (often 403-blocked), GetLatka (often accessible), TechCrunch + The SaaS News + sector trades, fund websites (Sprints Capital, Sequoia, etc.).
Per vendor:
Cross-vendor:
# Funding & Capital — [Category / Project]
> Generated [date] | X of N citations URL-verified
## Summary
[Category funding pattern + cross-cutting investor signals]
## Per-competitor
### [Competitor] — [Funding mode]
- Most recent: [amount + date + lead]
- Total: [$X]
- ARR: [if known, with year + source]
- Headcount: [if known, with trend]
- Notable: [posture signal — growth-mode, mature, stale, etc.]
## Cross-competitor patterns
[Bimodal/converging signals, M&A clusters, investor concentration]_internal/url-verification-log.md. Categorical absence of verifiable citations across all vendors flips category-classification toward "bootstrap-dominant" (categorical-zero as positioning signal).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.