stocks-trend-screener

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests and analyzes articles from external financial news sources, creating a surface for indirect prompt injection where malicious content in news reports could influence agent behavior. Evidence chain: Ingestion points include WSJ, FT, and SEC filings; weak boundary markers exist via verbatim quote requirements; capability inventory includes file writes and shell execution. Mitigation instructions such as 'skeptical by default' are included to reduce accidental obedience.\n- [PROMPT_INJECTION]: The 'Auto-Research' feature enables the agent to autonomously edit its own SKILL.md instruction file. This persistent self-modification allows the LLM to change its operating logic over time based on local evaluation metrics, which could be exploited if the evaluation process is compromised.\n- [COMMAND_EXECUTION]: Internal Python scripts like mention_velocity.py utilize subprocess.run to call system commands and interact with other installed agent skills (e.g., executing bun to run scripts from the read-news skill).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:22 PM
Security Audit — agent-trust-hub — stocks-trend-screener