SAFE version 1.0.1 · audited 2026-09-17
The market-research skill is a set of Markdown instructions and templates that guide an AI agent through market sizing, competitor analysis, demand validation, pricing research, and decision recommendations. It contains no executable code, scripts, binaries, file writes, environment variable use, wallet access, or persistence mechanisms in the reviewed package. The only external activity it calls for is live web research when current market data is required or the user asks for external evidence, and it limits competitor research to public, ethical sources. It suggests installing related ClawHub skills only if the user confirms. No hidden network destinations, credential handling, payment redirection, or attempts to override the agent's rules were found.
| Declared purpose | Research markets with sizing, segmentation, competitor mapping, pricing checks, and demand validation to produce decision-ready evidence for market entry, pricing, and expansion questions. |
| Observed behavior | The package is a set of Markdown guidance files. It instructs an agent to anchor research to a decision, size markets as TAM/SAM/SOM, triangulate evidence, segment customers, map competitors, validate demand, and finish with a decision-ready recommendation. It permits live web research only when current market data is needed or the user asks for external evidence, restricts competitor work to public and ethical sources, states it does not persist data or store secrets by default, and suggests related skills only with user confirmation. |
| Verdict, rules only | SAFE |
| Verdict, AI | SAFE |
| Final verdict | SAFE (never better than either pass) |
| capability | vs purpose | detail |
|---|---|---|
| network | needed | Live web research is allowed only when the task requires current market data or the user asks for external evidence (SKILL.md line 160). The package contains no network code; it relies on the host agent's tools. |
| browser | needed | The guidance directs the agent to public websites and platforms for review mining, competitor sources, and interview subject outreach. The package contains no browser automation code. |
| filesystem_read | needed | The skill directs the agent to use the smallest relevant included file for the task (SKILL.md line 19), so the host agent must read the local Markdown artifacts. |
| severity | finding |
|---|---|
| info | Documented homepage link Frontmatter declares a homepage URL; this is visible metadata, not an automatic outbound request. SKILL.md:5 homepage: https://clawic.com/skills/market-research |
| info | Declared purpose matches observed content This fragment from the frontmatter description matches the package's stated market-research purpose and the later guidance files. SKILL.md:6 Research markets with sizing, segmentation, competitor mapping, pricing checks, and demand validation that turn fuzzy ideas into decision-ready evidence. |
| info | Includes file-read guidance The skill directs the agent to read the smallest relevant included artifact, implying normal local file reads for the guidance documents. SKILL.md:19 Use the smallest relevant file for the task. |
| info | No default persistence claimed The security section states the skill does not create persistent memory or maintain a local workspace by default. SKILL.md:157 - create persistent memory or maintain a local workspace by default |
| info | No secret storage by default The skill states it will not store secrets unless the user explicitly asks for that workflow; the package contains no credential-handling code. SKILL.md:158 - store secrets unless the user explicitly asks for that workflow |
| info | Conditional network use This is the primary capability boundary for live research; it is conditioned on current data need or user request and fits the declared purpose. SKILL.md:160 Live web research is appropriate only when the task requires current market data or the user asks for external evidence. |
| low | Suggests installing related skills with user confirmation The related-skills section recommends installing other ClawHub skills but conditions the command on user confirmation; no automatic installation behavior is present. SKILL.md:163 Install with `clawhub install <slug>` if user confirms: |
| info | Publisher profile link The skill card links to the publisher profile on ClawHub; this is visible documentation, not a hidden destination. skill-card.md:9 [ivangdavila](https://clawhub.ai/user/ivangdavila) |
| info | Ethical research constraints This bounds competitor research to public, ethical sources and bans deceptive or unauthorized collection methods. skill-card.md:31 Mitigation: Use public information such as filings, pricing pages, reviews, forums, press releases, and conference material; avoid fake inquiries, social engine |
| info | Explicitly bans fake research practices The competitive-intelligence checklist labels fake customer inquiries as prohibited; nearby lines also ban social engineering, paywalled scraping, and accessing internal documents. competitor-analysis.md:60 ❌ Fake customer inquiries |
| info | Public platform outreach Validation guidance directs the agent to public networking platforms for interview subject recruitment, which is within the declared market-research purpose. validation.md:23 - LinkedIn (filter by role + industry + company size) |
0 AI finding(s) were dropped because their file, line or quote did not match the package.
| domain | service rating | where |
|---|---|---|
| clawhub.ai | not in the service index | skill-card.md:9 |
| clawic.com | not in the service index | SKILL.md:5 |
| Binaries invoked | none |
| Environment variables read | none |
| Hard-coded wallets | none |
| Pipes a download to a shell | 0 |
| eval / exec / subprocess | 0 |
| base64 blobs | 0 |
| File writes | 0 |
| Persistence | 0 |
| file | lines | sha256 |
|---|---|---|
SKILL.md | 173 | 9cb0edb3c0d18495… |
_meta.json | 6 | 9ee678c1a504cb5a… |
competitor-analysis.md | 89 | 995fc92cb50f685e… |
evidence-grading.md | 30 | 6ff41dd0e76cb583… |
skill-card.md | 58 | 361269076ddd737d… |
validation.md | 111 | dcbaa98fba9b8834… |
For agents
JSON: https://agenteconomy.report/k/market-research.audit.json · badge: https://agenteconomy.report/k/market-research.audited.svg ·
skill rating: /k/market-research · commission an audit of any skill: US$ 29 per version.
The complete published package of this exact version was downloaded from the registry and read statically; nothing was executed. A deterministic pass extracts network destinations, binaries, environment variables, writes, install commands, obfuscation markers, subprocesses and wallets, each with file and line. An AI then reads the whole package with those facts and writes the summary, the capabilities and the findings under a strict schema; every finding it produces must cite a file, a line and the exact text, or it is dropped. The final verdict is the worst of the two passes. The audit does not change the skill's trust tier (policy); the author may respond through the dispute channel and the response is published here. Commissioned by: the Agent Economy Report (free program: the 150 most downloaded skills, September 2026).