alphagbm-investment-thesis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays investment theses (prose) and AI-generated feedback (markdown) from the AlphaGBM API. This data processing creates a surface for indirect prompt injection if the retrieved content contains instructions designed to influence the agent's behavior, although this is inherent to the skill's primary function of tracking research data.
- [SAFE]: Network communication is restricted to vendor-owned domains, specifically
alphagbm.zeabur.appandalphagbm.com, for API operations and documentation. - [SAFE]: The skill implements secure authentication practices by requiring the
ALPHAGBM_API_KEYto be provided via an environment variable rather than being hardcoded in the instructions. - [SAFE]: The trigger phrases include legitimate Chinese translations for investment-related terms such as 'investment argument' and 'sell conditions', which are used for natural language invocation and do not represent obfuscation.
Audit Metadata