finance-investment-researcher
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses natural instructional language to define the agent's persona ('Quinn') and operational rules. No patterns associated with jailbreaking, safety bypass, or instruction overriding were detected.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, API keys, or access to sensitive local file paths (e.g., SSH keys, environment files) were found. The skill references legitimate external data sources like SEC EDGAR and Bloomberg.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill mentions standard data science libraries (pandas, numpy, etc.) for analysis. No suspicious remote code execution patterns, such as downloading and piping scripts to a shell, are present.
- [OBFUSCATION]: The content was scanned for Base64 encoding, zero-width characters, homoglyphs, and other obfuscation techniques; no such patterns were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data, including web scraping and sentiment analysis, which constitutes a standard attack surface for indirect prompt injection. However, the instructions emphasize primary source verification (SEC filings) and rigorous due diligence, which serves as a functional mitigation for the processing of untrusted data.
- [METADATA_POISONING]: The metadata fields are consistent with the skill's stated purpose and do not contain deceptive instructions or hidden malicious content.
Audit Metadata