optimize

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill takes user input via $ARGUMENTS (strategy, symbol, exchange, interval) and uses these values to dynamically construct directory paths and filenames. This creates a surface for indirect prompt injection where malicious input could lead to unauthorized file operations.
  • Ingestion points: User input through strategy, symbol, exchange, and interval parameters in SKILL.md.
  • Boundary markers: No delimiters or ignore instructions are defined for the generated content.
  • Capability inventory: Allowed tools include Bash, Write, and Edit for script creation and execution.
  • Sanitization: No input validation is specified for the interpolated variables.
  • [DYNAMIC_EXECUTION]: The skill generates Python scripts at runtime to perform backtesting and optimization. Script generation from templates is a core feature but constitutes dynamic code execution, which can be risky if influenced by untrusted external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:53 AM