portfolio-manager
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Alpaca API and user-provided CSV files to generate analysis reports. This presents a potential surface for indirect injection if ingested fields like company names or symbols were to contain malicious instructions. However, the data sources are trusted service providers or the user's own inputs.
- Ingestion points: Position data fetched via the Alpaca MCP tools and user-supplied CSV files.
- Capability inventory: Writing generated markdown reports to the repository root.
- Boundary markers: The skill structures output into clearly defined sections based on its analysis frameworks.
- Sanitization: Not explicitly mentioned for the ingested position data.
- [EXTERNAL_DOWNLOADS]: The documentation references standard and official resources such as the
requestsandalpaca-trade-apiPython packages, as well as official Alpaca API endpoints. These are well-known and expected dependencies for the skill's purpose. - [COMMAND_EXECUTION]: The skill includes a utility script (
test_alpaca_connection.py) for the user to verify their API setup. This script performs standard network operations to verify account connectivity with official domains.
Audit Metadata