investment-memo

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill involves ingesting external data from web searches and user inputs to generate investment documents. This represents a functional surface for indirect prompt injection, where untrusted content from the web could attempt to influence the agent's behavior during document generation.
  • Ingestion points: External web search results and user-supplied company or industry information (referenced in SKILL.md).
  • Boundary markers: No specific boundary markers or instructions to isolate or ignore untrusted payloads are present.
  • Capability inventory: The skill is capable of generating document files (DOCX, PDF, PPTX) and performing web searches.
  • Sanitization: No data validation or sanitization mechanisms are defined for the processed external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 12:26 PM
Security Audit — agent-trust-hub — investment-memo