deep-company-series

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes tools like web_search, get_research_reports, and get_financial_statements to fetch financial data and market analysis. These are legitimate operations aligned with the skill's stated purpose of investment research.
  • [COMMAND_EXECUTION]: The skill mentions platform-specific tools such as report_audit and financial_rigor for auditing reports and performing cross-validation of financial metrics. These tools are used for data validation rather than arbitrary command execution.
  • [DATA_EXPOSURE]: File operations are restricted to reading and writing the generated research reports within a dedicated reports/ directory. No sensitive system files, environment variables, or credentials are accessed.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns typical of prompt injection, such as attempts to bypass safety filters, override system constraints, or extract system prompts. The logic is focused on content structure and factual accuracy.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources (financial filings and research reports). While this presents a surface for indirect injection, the skill mitigates risk through a 'Strict Fact-Check Checklist' and manual/automated cross-validation steps that verify data against multiple anchors and official filings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 10:24 PM
Security Audit — agent-trust-hub — deep-company-series