analyse-smartmoney-darkpool

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch market data and ZIP/CSV files from squeezemetrics.com and finra-markets.morningstar.com. These are established financial data sources relevant to the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for processing untrusted data from external websites.
  • Ingestion points: The agent fetches data from https://squeezemetrics.com/monitor/download/dix.zip and https://finra-markets.morningstar.com/finra/finia_finra_short_volume.jsp (as defined in SKILL.md).
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potential commands embedded within the external data sources.
  • Capability inventory: The agent is granted capabilities to fetch and parse external content to produce a market verdict (ACCUMULATING/DISTRIBUTING/NEUTRAL).
  • Sanitization: There are no specified sanitization or validation steps for the remote content before it is incorporated into the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — analyse-smartmoney-darkpool