market-research-reports
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool and Python'ssubprocessmodule to generate report visualizations and compile LaTeX source files into PDF documents. These operations are essential to the skill's primary function. The implementation inscripts/generate_market_visuals.pyusessubprocess.run()with a list of arguments, which is a secure method that prevents shell injection vulnerabilities. - [PROMPT_INJECTION]: The skill processes a user-provided market topic and interpolates it into prompts for secondary tools (e.g.,
research-lookupandscientific-schematics), creating a potential surface for indirect prompt injection. - Ingestion points: The
[MARKET NAME]placeholder inSKILL.mdand the--topicargument inscripts/generate_market_visuals.py. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish the user-supplied topic from system instructions.
- Capability inventory: The skill possesses capabilities for file system access (
Read,Write,Edit) and shell execution (Bash). - Sanitization: The skill relies on standard argument parsing but does not perform content-level sanitization of the topic string prior to its inclusion in downstream tool prompts.
Audit Metadata