skills/bankrbot/skills/aeon-deal-flow/Gen Agent Trust Hub

aeon-deal-flow

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources such as SEC Form D filings, news sites (Crunchbase, TechCrunch), and social media posts (X, LinkedIn).
  • Ingestion points: Data is pulled from external URLs listed in the 'Sources' section of SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified in the prompt template.
  • Capability inventory: The skill primarily performs data synthesis and formatting; no dangerous shell execution or file-write capabilities are present in the provided files.
  • Sanitization: There is no evidence of sanitization or filtering for malicious prompt instructions within the ingested content.
  • [EXTERNAL_DOWNLOADS]: The catalog.json file points to a GitHub repository for installation and setup.
  • Evidence: The installation source is 'https://github.com/BankrBot/skills/tree/main/aeon-deal-flow'. This refers to the vendor's own repository and is a standard mechanism for skill distribution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-deal-flow