bull-bear

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill correctly uses vendor-owned resources, such as the daloopa.com domain for data citations and specific internal tools for financial data retrieval. All operations, including local report generation, are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill ingests third-party data from SEC filings and external search results, representing a surface for indirect prompt injection. This is a low-risk factor inherent to the skill's objective of analyzing external documents.
  • Ingestion points: SEC filings and qualitative research results defined in Step 4 of SKILL.md.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings for the agent when processing external content.
  • Capability inventory: The skill has the ability to write HTML reports to the local file system in the reports/ directory.
  • Sanitization: Not specified; there are no instructions to escape or validate external content before its inclusion in the generated reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:39 AM
Security Audit — agent-trust-hub — bull-bear