stock-research-desk

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from raw data seats and external news URLs, creating a surface for potential indirect prompt injection attacks. However, it mandates strict structured citations and verbatim quoting, which serve as boundary markers to prevent the agent from executing instructions embedded in data. \n
  • Ingestion points: External news articles (via fetched URLs) and raw equity research data seats. \n
  • Boundary markers: The skill requires a mandatory citation format [TIER] https://exact-url (YYYY-MM-DD) — "verbatim quote" which structurally isolates external content. \n
  • Capability inventory: None; the skill consists only of instructional text and contains no shell scripts, network-active code, or file-writing logic. \n
  • Sanitization: The instructions explicitly require verbatim quotes to prevent the agent from interpreting or paraphrasing potentially malicious inputs.- [NO_CODE]: This skill is entirely instructional, containing only markdown documentation and YAML configuration. The absence of executable scripts, binaries, or automated shell commands eliminates common attack vectors like remote code execution or privilege escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — stock-research-desk