strategy-generate
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a
bashcommand to validate the syntax of the generatedsignal_engine.pyfile usingast.parse. While this specific command is functionally a safety check, it demonstrates an active shell execution capability. - [INDIRECT_PROMPT_INJECTION]: The core workflow involves the agent parsing untrusted user strategy descriptions and converting them into executable Python code. There are no explicit instructions or mechanisms mentioned to sanitize the user's input or prevent the inclusion of malicious system-level commands within the generated trading logic.
- Ingestion points: User intent and strategy descriptions processed in the 'Requirements Parsing' stage.
- Boundary markers: None specified to separate user-provided logic from the script generation context.
- Capability inventory:
bash(syntax validation),write_file(code and config creation), and abacktesttool that executes the generated Python script. - Sanitization: No sanitization, escaping, or filtering of user requirements is described before they are interpolated into the generated code.
- [DYNAMIC_EXECUTION]: The skill is designed to write a Python script at runtime (
code/signal_engine.py) and then execute it via thebacktesttool. This runtime code generation and execution cycle is the primary intended function but represents a significant attack surface if the code generation is influenced by adversarial input.
Audit Metadata