company-filing-research

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the filings and disclosures it is designed to ingest.
  • Ingestion points: SKILL.md specifies a workflow to collect and read external company filings such as 10-K, 10-Q, and 8-K reports.
  • Boundary markers: No delimiters or instructions are provided to the agent to help it distinguish between the skill's primary instructions and potentially adversarial content within the ingested filings.
  • Capability inventory: The skill has the capability to write summarized evidence to the local filesystem at research/targets/evidence/filings/ as defined in the SKILL.md workflow.
  • Sanitization: The skill lacks instructions to sanitize or validate the content of external filings before they are incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 10:23 PM
Security Audit — agent-trust-hub — company-filing-research