analyse-smartmoney

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a coordination module that routes financial queries to specialized sub-skills for Form 4, 13F, and other market data. It does not perform arbitrary shell command execution, high-privilege file operations, or unauthorized network activity.
  • [SAFE]: The skill implements a comprehensive set of honesty rules and failure-mode checks, including specific warnings about data lag, signal crowding, and the 'hedge-as-signal' fallacy. It also references authoritative and well-known government domains (e.g., sec.gov, cftc.gov) for its data methodology.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface as it synthesizes information from various external specialist spokes. 1. Ingestion points: Specialist spoke outputs (SKILL.md). 2. Boundary markers: Verbatim output contract and 'Honesty rules' (SKILL.md) define the expected structure for agent responses. 3. Capability inventory: The skill routes to other sub-skills but lacks direct capabilities for writing files, spawning subprocesses, or executing remote scripts. 4. Sanitization: Mitigation is handled via reliability weighting and a strict cross-class confirmation requirement across independent signal types (references/04-synthesis-and-failure-modes.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — analyse-smartmoney