alphagbm-company-profile
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill interacts with 'alphagbm.zeabur.app' and 'alphagbm.com', which are official vendor resources for AlphaGBM. Network operations are limited to these service-providing domains.
- [SAFE]: The skill utilizes environment variables ('ALPHAGBM_API_KEY') for credential management, ensuring that API keys are not exposed in the skill configuration.
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting and presenting summaries from the AlphaGBM API. * Ingestion points: Markdown summaries received from 'alphagbm.zeabur.app'. * Boundary markers: No delimiters or instructions are used to separate API content from agent instructions. * Capability inventory: Profile management and market data lookup capabilities. * Sanitization: No content validation or sanitization is performed on the summaries retrieved from the API.
Audit Metadata