strategy-generate

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a bash command to validate the syntax of the generated signal_engine.py file using ast.parse. While this specific command is functionally a safety check, it demonstrates an active shell execution capability.
  • [INDIRECT_PROMPT_INJECTION]: The core workflow involves the agent parsing untrusted user strategy descriptions and converting them into executable Python code. There are no explicit instructions or mechanisms mentioned to sanitize the user's input or prevent the inclusion of malicious system-level commands within the generated trading logic.
  • Ingestion points: User intent and strategy descriptions processed in the 'Requirements Parsing' stage.
  • Boundary markers: None specified to separate user-provided logic from the script generation context.
  • Capability inventory: bash (syntax validation), write_file (code and config creation), and a backtest tool that executes the generated Python script.
  • Sanitization: No sanitization, escaping, or filtering of user requirements is described before they are interpolated into the generated code.
  • [DYNAMIC_EXECUTION]: The skill is designed to write a Python script at runtime (code/signal_engine.py) and then execute it via the backtest tool. This runtime code generation and execution cycle is the primary intended function but represents a significant attack surface if the code generation is influenced by adversarial input.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:39 AM
Security Audit — agent-trust-hub — strategy-generate