alphagbm-company-profile

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill interacts with 'alphagbm.zeabur.app' and 'alphagbm.com', which are official vendor resources for AlphaGBM. Network operations are limited to these service-providing domains.
  • [SAFE]: The skill utilizes environment variables ('ALPHAGBM_API_KEY') for credential management, ensuring that API keys are not exposed in the skill configuration.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting and presenting summaries from the AlphaGBM API. * Ingestion points: Markdown summaries received from 'alphagbm.zeabur.app'. * Boundary markers: No delimiters or instructions are used to separate API content from agent instructions. * Capability inventory: Profile management and market data lookup capabilities. * Sanitization: No content validation or sanitization is performed on the summaries retrieved from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 11:42 AM
Security Audit — agent-trust-hub — alphagbm-company-profile