business-narrative

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from external sources.
  • Ingestion points: The skill retrieves current financial filings (10-K, 10-Q, 56-1 One Report), investor relations decks, earnings call transcripts, and competitive landscape data via web search (SKILL.md Step 1, references/research_checklist.md).
  • Boundary markers: The instructions lack explicit directives for the agent to use delimiters or to disregard potential instructions embedded within the researched documents.
  • Capability inventory: The skill focuses on research, reasoning, and producing a structured Narrative Brief. It does not explicitly call for high-risk capabilities like arbitrary command execution or local file system writes, though its output is intended to influence a downstream company-valuation process.
  • Sanitization: No specific content filtering or sanitization steps are defined for the data retrieved from external web sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 01:14 AM
Security Audit — agent-trust-hub — business-narrative