options-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
SignalEngineinterface processes external market data, creating a potential surface for indirect prompt injection. \n - Ingestion points: Market data is ingested through the
data_mapargument in thegeneratemethod ofcode/signal_engine.py.\n - Boundary markers: No explicit delimiters or instructions are provided to the model to ignore potential injection within the ingested data.\n
- Capability inventory: The signal output controls trading instructions (date, action, underlying, legs) which influence the backtest execution and artifact generation.\n
- Sanitization: The provided documentation does not specify sanitization or validation logic for the input market data.\n- [DYNAMIC_EXECUTION]: The skill framework relies on the execution of logic defined in a separate file,
code/signal_engine.py. This script is intended to be loaded and executed by theoptionsengine at runtime to generate trading signals based on the provided data map.
Audit Metadata