research-note
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs network operations via the
WebSearchtool in Phase H to collect real-time news headlines, sentiment, and macro-economic policy information. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the ingestion and processing of untrusted data from the public web.
- Ingestion points: External data from
WebSearchqueries is integrated into the context used for report generation in Phase H (News & Catalysts). - Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" markers for the content returned by the search tool.
- Capability inventory: The agent performs complex financial synthesis, multi-step calculations (DCF, WACC), and renders stylized HTML reports based on the gathered data.
- Sanitization: The skill enforces a mandatory source quality policy that restricts citations to primary sources and Tier-1 financial press, which serves as a mitigation against malicious or low-quality data.
Audit Metadata