options-payoff
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs the dynamic context injection syntax (
!command) to retrieve live market data during the skill initialization process. - Evidence: In
SKILL.md, the skill executespython3 -c "exec('try:\n import yfinance as yf\n p=yf.Ticker(\'^GSPC\').fast_info[\'lastPrice\']\n print(f\'SPX ≈ {p:.0f}\')\nexcept Exception:\n print(\'SPX price unavailable — check market data\')')". This command fetches the current S&P 500 price using theyfinancelibrary to provide a baseline for the options payoff calculations. This is a legitimate, project-specific use of dynamic context for a financial analysis tool. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of user-provided text descriptions and screenshots of brokerage positions, which establishes a potential injection surface.
- Ingestion points: The skill extracts parameters from user-provided screenshots (IBKR, TastyTrade, Robinhood) and textual strategy descriptions as defined in
SKILL.md. - Boundary markers: While the skill provides clear instructions on which fields to extract, it does not explicitly instruct the agent to ignore or delimit instructions that might be embedded within the extracted ticker names, strikes, or premium values.
- Capability inventory: The skill has the capability to render interactive HTML and JavaScript widgets via the
visualize:show_widgetandvisualize:read_metools. - Sanitization: The skill does not describe specific sanitization or validation routines for the data extracted from screenshots before it is passed to the visualization engine.
Audit Metadata