skills/hkuds/vibe-trading/pine-script/Gen Agent Trust Hub

pine-script

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local files to generate trading platform code, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: The agent is instructed to read config.json and code/signal_engine.py (referenced in SKILL.md) to understand strategy logic.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are provided to wrap the ingested content before it is processed by the model.
  • Capability inventory: The skill utilizes read_file to access strategy logic and write_file to save generated artifacts to the local file system.
  • Sanitization: There is no evidence of sanitization or validation of the input logic or parameters before they are used to generate code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:20 PM
Security Audit — agent-trust-hub — pine-script