market-movers

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external sources and local files that could contain malicious instructions.
  • Ingestion points: The skill reads project-specific information from app-marketing-context.md and fetches external App Store data (app names, descriptions, and chart details) using MCP tools such as get_market_movers and get_app.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands when processing the external app data or context files.
  • Capability inventory: While the skill itself does not contain scripts for file writing or network operations, it utilizes MCP tools to interact with the environment based on the processed data.
  • Sanitization: The instructions do not include requirements for sanitizing or validating the content retrieved from external market snapshots or the local marketing context file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:32 PM
Security Audit — agent-trust-hub — market-movers