mr-market

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and historical/projected examples for psychological framing in investment decisions. It does not contain any executable logic or scripts.
  • [DATA_EXPOSURE]: No access to sensitive files, environment variables, or credentials was detected. The skill operates purely on user-provided financial context.
  • [COMMAND_EXECUTION]: The skill does not use any shell commands, subprocesses, or dynamic context injection (!command) syntax.
  • [REMOTE_CODE_EXECUTION]: There are no remote script downloads, package installations, or external dependencies. External links point to the vendor's official domain (deciqai.com) or well-known services (NYT, CNBC, Berkshire Hathaway).
  • [OBFUSCATION]: No base64, hex-encoding, zero-width characters, or other obfuscation techniques were found in the instructions or metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input regarding market quotes and business reality. However, it lacks exploitable capabilities like network operations or file writes, and it utilizes structured output templates which serve as natural boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:15 AM
Security Audit — agent-trust-hub — mr-market