skills/daloopa/investing/inflection/Gen Agent Trust Hub

inflection

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external content from SEC filings and user-supplied arguments.
  • Ingestion points: User-provided ticker and management commentary retrieved from SEC filings.
  • Boundary markers: No explicit delimiters are used to isolate external filing content from the agent's instructions.
  • Capability inventory: The skill is permitted to write to the local reports directory and perform network searches for financial documentation.
  • Sanitization: No data validation is applied to the retrieved commentary before inclusion in the final HTML report.
  • [SAFE]: The skill links to daloopa.com for data attribution, which is consistent with the author's verified infrastructure. The core functionality of growth calculation and report generation is consistent with its stated financial purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:19 PM
Security Audit — agent-trust-hub — inflection