equity-valuation-framework

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for transforming financial data into valuation reports. It does not include any code, scripts, or tool calls that could perform network exfiltration, file system modification, or command execution.
  • [PROMPT_INJECTION]: The skill defines an input contract that ingests untrusted data from news digests and metadata, creating a surface for indirect prompt injection. However, this is assessed as safe because the skill has no exploitable capabilities. Ingestion points: The news_digest and metadata fields in the Required input contract section of SKILL.md. Boundary markers: Absent. The skill does not instruct the agent to ignore instructions embedded in the input data. Capability inventory: None. The skill does not request or use any tools or subprocesses. Sanitization: The skill includes a Data quality gate for verifying financial consistency but does not provide sanitization for textual instruction injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 04:53 PM
Security Audit — agent-trust-hub — equity-valuation-framework