backtesting-frameworks
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The file
skill-report.jsoncontains a simulated security audit report that explicitly claims a 'safe' verdict and provides fake finding justifications to dismiss potential security concerns. This is a self-referential injection attempt (Category 8e) aimed at biasing automated and human security reviewers. - Ingestion points: Metadata processing of the
skill-report.jsonfile. - Boundary markers: None; the authoritative-looking claims are presented as raw data within the skill package.
- Capability inventory: The skill includes Python implementation patterns in
resources/implementation-playbook.mdutilizingpandasandnumpy. No dangerous system capabilities (e.g., subprocess, network, file-system writes) were detected in these patterns. - Sanitization: None; the skill relies on the analyzer correctly identifying the simulated audit as untrusted data.
Audit Metadata