alphagbm-investment-thesis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays investment theses (prose) and AI-generated feedback (markdown) from the AlphaGBM API. This data processing creates a surface for indirect prompt injection if the retrieved content contains instructions designed to influence the agent's behavior, although this is inherent to the skill's primary function of tracking research data.
  • [SAFE]: Network communication is restricted to vendor-owned domains, specifically alphagbm.zeabur.app and alphagbm.com, for API operations and documentation.
  • [SAFE]: The skill implements secure authentication practices by requiring the ALPHAGBM_API_KEY to be provided via an environment variable rather than being hardcoded in the instructions.
  • [SAFE]: The trigger phrases include legitimate Chinese translations for investment-related terms such as 'investment argument' and 'sell conditions', which are used for natural language invocation and do not represent obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:59 PM
Security Audit — agent-trust-hub — alphagbm-investment-thesis