desk-operating-model
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests external market data and news, creating a potential surface for indirect prompt injection attacks through untrusted data sources.\n
- Ingestion points: Market briefs, research files, news feeds, and catalyst calendars processed by the Research Analyst role.\n
- Boundary markers: The 'Evidence standard' section establishes clear guidelines for separating data from interpretation and requires source attribution for all numerical figures.\n
- Capability inventory: The system includes an Execution Trader role authorized to write to financial exchange endpoints.\n
- Sanitization: The protocol relies on manual ticket review and user approval to validate actions derived from processed data.\n- [COMMAND_EXECUTION]: The Execution Trader bot is explicitly granted the capability to execute commands against the Hyperliquid exchange endpoint.\n
- Evidence: The instruction specifies that the Execution Trader is the only bot allowed to send to the
/exchangepath, gated by mandatory user approval rules.\n- [DYNAMIC_EXECUTION]: The Strategist role is responsible for running backtests and paper trades involving user-defined strategy code.\n - Evidence: The skill references a shared workspace directory
/workspace/trading-desk/strategies/containing strategy rules and code for execution.
Audit Metadata