sentiment-analyst

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external social platforms via the derivatives_sentiment tool (action: 'reddit_trending'). There are no boundary markers or instructions to delimit this content or treat it as untrusted, creating an ingestion point for indirect prompt injection. While the skill primarily uses this data for report generation and lacks direct file-write or system-level capabilities, the absence of sanitization or explicit 'ignore instructions' warnings poses a minor risk.
  • [PROMPT_INJECTION]: The skill implements a 'Vendor Neutrality' policy that instructs the agent to systematically hide the identities of data sources and providers. This includes specific directions to suppress the names of external services in error messages (e.g., masking 'ApeWisdom' or 'Binance' with generic terms). These instructions force the agent to withhold specific diagnostic and source information from the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 09:08 AM
Security Audit — agent-trust-hub — sentiment-analyst