stock-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill frontmatter and instructions contain no prompt injection patterns, unauthorized command execution, or sensitive data access.
  • [SAFE]: No obfuscated content, persistence mechanisms, or privilege escalation attempts were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface as it ingests untrusted external data. Evidence Chain: (1) Ingestion points: Financial data processed through read_xlsx and analyze_spreadsheet tools in SKILL.md. (2) Boundary markers: Absent. (3) Capability inventory: Spreadsheet reading/writing and chart creation. (4) Sanitization: Absent. As these capabilities are the primary intended purpose of the skill and lack dangerous system-level access, the finding does not escalate the verdict.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:46 PM
Security Audit — agent-trust-hub — stock-analysis