boss-mo-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [NO_CODE]: The instructions in SKILL.md are purely declarative, defining a persona and decision-making framework for trading analysis without embedding executable scripts or malicious logic.
  • [COMMAND_EXECUTION]: The repository includes helper scripts (scripts/pre_extract.py and scripts/screenshot.mjs) used for project maintenance, such as scanning research files and generating screenshots of UI components. These scripts are tools for the developer and are not invoked by the AI agent during runtime interactions.
  • [EXTERNAL_DOWNLOADS]: The documentation provides standard installation instructions using git clone and npx to add the skill to an agent's environment. These are routine methods for skill distribution and do not point to untrusted third-party binaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to use a WebSearch tool to fetch real-time market data. While this creates a surface for indirect prompt injection from external search results, it is a necessary functional requirement for the skill's stated purpose of financial analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 12:22 PM
Security Audit — agent-trust-hub — boss-mo-perspective