pricing-power-tracker
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses clear, instructional language focused on financial workflows. No attempts to override agent behavior, bypass safety guidelines, or extract system prompts were detected.
- [DATA_EXFILTRATION]: The skill utilizes an MCP tool provided by the vendor (MarketcheckHub). While it reads a local project memory file (
marketcheck-profile.md), this is a standard practice for personalizing agent analysis and does not involve unauthorized network transmission of sensitive credentials or environment variables. - [REMOTE_CODE_EXECUTION]: No patterns of downloading or executing external scripts, packages, or payloads were found. The skill operates entirely through structured data processing and text output.
- [COMMAND_EXECUTION]: No arbitrary shell command execution, privilege escalation, or dynamic context injection patterns (e.g., shell command placeholders) are present.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses via the Marketcheck MCP tool and user profiles. While these are external data sources, the skill is focused on numerical calculation and trend reporting, posing a low risk of executing instructions embedded in processed data.
Audit Metadata