investing-team
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates a robust security posture by using a dedicated 'evaluator' agent to run quality gates on all outputs. This ensures that analytical products comply with mandatory checklists for primary-source citations and thesis soundness, providing a strong defense against hallucination and data laundering.
- [SAFE]: The skill processes untrusted user data via 'fixtures' (CSV or text pastes), which is a common surface for indirect prompt injection. However, this risk is well-mitigated through the use of strict output templates, boundary markers, and the mandatory evaluation phase by a separate agent. No dangerous capabilities such as arbitrary file writes or shell execution were detected.
- [CREDENTIALS_UNSAFE]: A thorough review of all 26 files confirms no hardcoded API keys or secrets are present. The 'standards/data-sources-and-fixtures.md' standard specifically mandates that credentials like 'FRED_API_KEY' must be managed via environment variables and never embedded in code or artifacts.
- [EXTERNAL_DOWNLOADS]: The skill fetches data from trusted and well-known financial services, including the SEC EDGAR portal, FRED Economic Data (St. Louis Fed), and the Taiwan Stock Exchange (MOPS/TWSE). These references are documented neutrally as authoritative primary sources.
- [PROMPT_INJECTION]: The skill's instructions are focused entirely on investment methodology and analytical rigor. There are no attempts to bypass safety filters, extract system prompts, or override agent constraints.
- [DATA_EXFILTRATION]: No unauthorized network operations or data exfiltration patterns were identified. Data provenance is enforced via a mandatory footer in all reports, ensuring transparency in data handling.
Audit Metadata