market-research-reports

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool and Python's subprocess module to generate report visualizations and compile LaTeX source files into PDF documents. These operations are essential to the skill's primary function. The implementation in scripts/generate_market_visuals.py uses subprocess.run() with a list of arguments, which is a secure method that prevents shell injection vulnerabilities.
  • [PROMPT_INJECTION]: The skill processes a user-provided market topic and interpolates it into prompts for secondary tools (e.g., research-lookup and scientific-schematics), creating a potential surface for indirect prompt injection.
  • Ingestion points: The [MARKET NAME] placeholder in SKILL.md and the --topic argument in scripts/generate_market_visuals.py.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish the user-supplied topic from system instructions.
  • Capability inventory: The skill possesses capabilities for file system access (Read, Write, Edit) and shell execution (Bash).
  • Sanitization: The skill relies on standard argument parsing but does not perform content-level sanitization of the topic string prior to its inclusion in downstream tool prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:33 AM
Security Audit — agent-trust-hub — market-research-reports