alpha101

Warn

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts scripts/backtest_alpha.py and scripts/compute_ic.py use pd.read_pickle() to load input data from files specified via command-line arguments. In Python, the pickle module is insecure and can execute arbitrary code during deserialization. This poses a risk if an attacker provides a maliciously crafted pickle file to be processed by the agent using this skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 10:32 PM
Security Audit — agent-trust-hub — alpha101