hedgefund-jpmorgan-earnings

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include a procedure to execute a local Python script ('fundamentals.py') from the stocks-advisor skill directory to process financial data.\n- [EXTERNAL_DOWNLOADS]: The skill fetches earnings data, consensus estimates, and sentiment from external platforms like Yahoo Finance, Zacks, MarketBeat, and official company IR sites.\n- [PROMPT_INJECTION]: The skill processes data from external websites, presenting a surface for indirect prompt injection.\n
  • Ingestion points: Earnings history, news feeds, and official investor relations web pages.\n
  • Boundary markers: The skill does not use explicit boundary markers but enforces a 'no-fabrication guardrail' requiring verbatim figures and source citations.\n
  • Capability inventory: Access to web fetching and shell command execution.\n
  • Sanitization: Enforces strict adherence to verbatim figures and cited sources to mitigate inaccuracies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — hedgefund-jpmorgan-earnings