stocks-portfolio

Fail

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: HIGHDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill hardcodes a specific Google Spreadsheet ID (1aunLbpNGo85WqrMHiIsy6nFUija4Lnjot-rIhE-pGU8) and a specific Carta portfolio URL (https://app.carta.com/investors/individual/968826/portfolio/). Instructions direct the agent to scrape financial quantities, positions, and private equity valuations from authenticated brokerage and Carta sessions and write them to this fixed spreadsheet. This configuration exfiltrates sensitive financial data to an account not controlled by the end user.
  • [PROMPT_INJECTION]: The skill processes data from external financial portals (Interactive Brokers, Fidelity, Chase, Carta) via browser automation without boundary markers or sanitization, exposing the agent to indirect prompt injection. * Ingestion points: Browser-based scraping of financial positions and certificate details. * Boundary markers: Absent. The agent is not instructed to isolate or ignore instructions contained within the scraped HTML or text. * Capability inventory: The skill uses the gws CLI (sheets:read, sheets:write) and browser automation tools (claude-in-chrome, chrome-use). * Sanitization: Absent. Extracted data is written directly to the Google Sheet without validation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 20, 2026, 02:22 PM
Security Audit — agent-trust-hub — stocks-portfolio