us-market-bubble-detector

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The skill instructs the agent to use web_search to collect real-time financial metrics (e.g., Put/Call ratio, VIX, Margin Debt, IPO stats) as defined in Phase 1: Mandatory Quantitative Data Collection in both SKILL.md and README.md.
  • Boundary markers: The instructions lack explicit boundary markers or directives for the agent to ignore potential natural language instructions embedded within the results of its web searches.
  • Capability inventory: The agent uses the gathered data for internal scoring and reporting. There are no identified dangerous capabilities (such as eval, exec, or file-system modifications) that could be triggered by data retrieved from the web.
  • Sanitization: There is no explicit sanitization or validation logic described for the external content before it is processed by the agent's internal reasoning engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 10:27 AM
Security Audit — agent-trust-hub — us-market-bubble-detector