stocks-trend-screener
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests and analyzes articles from external financial news sources, creating a surface for indirect prompt injection where malicious content in news reports could influence agent behavior. Evidence chain: Ingestion points include WSJ, FT, and SEC filings; weak boundary markers exist via verbatim quote requirements; capability inventory includes file writes and shell execution. Mitigation instructions such as 'skeptical by default' are included to reduce accidental obedience.\n- [PROMPT_INJECTION]: The 'Auto-Research' feature enables the agent to autonomously edit its own
SKILL.mdinstruction file. This persistent self-modification allows the LLM to change its operating logic over time based on local evaluation metrics, which could be exploited if the evaluation process is compromised.\n- [COMMAND_EXECUTION]: Internal Python scripts likemention_velocity.pyutilizesubprocess.runto call system commands and interact with other installed agent skills (e.g., executingbunto run scripts from theread-newsskill).
Audit Metadata