ai-trading-crew

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The system is vulnerable to indirect prompt injection via the 'Sentiment & News' team which processes untrusted external data.
  • Ingestion points: The skill ingests data from external news feeds, social sentiment, and analyst ratings through the Polygon.io API and NLP agents (SKILL.md).
  • Boundary markers: There are no defined boundary markers or instructions to the agents to ignore or escape embedded commands within the ingested sentiment data.
  • Capability inventory: The 'Execution & Ops' team has the authority to submit orders to the Alpaca broker based on the consensus reached by other agents.
  • Sanitization: No sanitization or validation mechanisms are described to filter out malicious payloads hidden in financial news or social media text.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 12:54 AM
Security Audit — agent-trust-hub — ai-trading-crew