portfolio-pulse

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external tools, creating a risk that malicious instructions within news articles or SEC filings could influence the agent's output.
  • Ingestion points: news_browse and sec_filing_read tools.
  • Boundary markers: Absent. No delimiters or instructions are provided to the agent to distinguish between its core logic and content retrieved from external sources.
  • Capability inventory: The skill uses personal_holdings and personal_profile tools to read sensitive user information.
  • Sanitization: Absent. The content retrieved from the web is not escaped or filtered before being processed by the agent.
  • [DATA_EXPOSURE]: The skill is designed to read private financial information using the personal_holdings and personal_profile tools. The instructions recommend delivery to an external service (Telegram), which facilitates the transfer of this sensitive data outside of the local environment.
  • [PERSISTENCE_MECHANISMS]: The skill includes instructions to configure a recurring execution schedule using the hermes cron command, allowing the agent logic to persist and run automatically on a weekly basis.
  • [EXTERNAL_DOWNLOADS]: The skill references an external repository at github.com/LLMQuant/skills for analysis methods. This repository is associated with the vendor 'LLMQuant'.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 09:27 PM
Security Audit — agent-trust-hub — portfolio-pulse