pine-script
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local files to generate trading platform code, which creates a surface for indirect prompt injection attacks.
- Ingestion points: The agent is instructed to read
config.jsonandcode/signal_engine.py(referenced in SKILL.md) to understand strategy logic. - Boundary markers: No specific delimiters or "ignore instructions" warnings are provided to wrap the ingested content before it is processed by the model.
- Capability inventory: The skill utilizes
read_fileto access strategy logic andwrite_fileto save generated artifacts to the local file system. - Sanitization: There is no evidence of sanitization or validation of the input logic or parameters before they are used to generate code.
Audit Metadata