technical-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data via user-provided chart images and generates file output, which creates a theoretical surface for indirect prompt injection if the agent attempts to follow instructions embedded within the images.
  • Ingestion points: User-provided weekly chart images processed in Step 1 of the analysis workflow.
  • Boundary markers: The skill includes strong instructions to base analysis "exclusively on technical data visible in the chart" and "ignore external information (news, fundamentals, sentiment)."
  • Capability inventory: The skill reads local framework and template files and writes markdown reports to the file system. It does not have network access or shell execution capabilities.
  • Sanitization: No specific sanitization logic for image-extracted text is provided, relying on the agent's core safety filters and specific negative constraints in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — technical-analyst