market-movers

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and operational logic are consistent with its stated purpose of market analysis. No malicious instructions, hidden commands, or security bypasses were identified.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads from 'app-marketing-context.md' to obtain project-specific details. This is an expected behavior for a marketing analysis tool and does not involve unauthorized access to sensitive system files or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external App Store chart tools and the local 'app-marketing-context.md' file. Although it lacks explicit boundary markers or sanitization logic, the risk is classified as negligible because the skill's capabilities are restricted to data retrieval and analysis, with no dangerous execution sinks identified. Ingestion points: app-marketing-context.md and outputs from the get_market_movers, get_market_activity, get_category_top, and get_app tools. Boundary markers: Absent. Capability inventory: Data retrieval and report generation. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:42 PM
Security Audit — agent-trust-hub — market-movers