technical-analyst
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely self-contained, relying on local reference files and user-provided images. No external dependencies or remote code patterns are used.
- [DATA_EXPOSURE]: No risk of data exfiltration or sensitive file exposure was detected. The skill operates without API keys and stores its output in a local 'reports/' directory.
- [REMOTE_CODE_EXECUTION]: The skill does not contain any instructions for downloading or executing remote scripts or code.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided images as its primary data source. This attack surface is addressed by strict 'Core Principles' that instruct the agent to ignore any content other than technical chart data. Ingestion points: User-provided images (SKILL.md). Boundary markers: 'Core Principles' and 'Objectivity Requirements' sections. Capability inventory: Local file write to 'reports/'. Sanitization: Behavioral instructions to ignore news, fundamentals, and non-technical chart elements.
Audit Metadata