backtest-diagnose

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill encourages the installation of arbitrary Python packages via pip install when it encounters an ImportError. These packages are determined by the agent from runtime error logs rather than a fixed, verified manifest, introducing a risk of malicious package installation.- [COMMAND_EXECUTION]: The skill uses bash() to execute shell commands for package installation and code validation tasks.- [CREDENTIALS_UNSAFE]: The skill accesses config.json specifically to diagnose issues related to API tokens, which confirms it interacts with files likely containing sensitive authentication credentials.- [DYNAMIC_EXECUTION]: The skill executes dynamically constructed Python code using a shell command to validate the abstract syntax tree (AST) of user-modified files.- [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted local files including code, configuration, and data artifacts to drive its automated repair logic, creating an attack surface where malicious input could manipulate the agent's actions.
  • Ingestion points: artifacts/metrics.csv, equity.csv, trades.csv, code/signal_engine.py, and config.json.
  • Boundary markers: None. No delimiters are used to separate untrusted file content from diagnostic instructions.
  • Capability inventory: edit_file, bash(), and refresh_strategy_evidence.
  • Sanitization: None. The skill processes the raw contents of files to identify and fix bugs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 06:26 PM
Security Audit — agent-trust-hub — backtest-diagnose