us-stock-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on fetching real-time data from external web sources (e.g., news articles, analyst ratings, and financial sites) which may contain hidden or malicious instructions designed to influence the agent's analytical output.
- Ingestion points: Data is ingested via web search tools as defined in the 'Data Sources' and 'Search Strategy' sections of SKILL.md.
- Boundary markers: The instructions lack specific boundary markers or directives for the agent to ignore instructions embedded within the retrieved external content.
- Capability inventory: The skill primarily performs data retrieval and text report generation; no dangerous capabilities such as arbitrary code execution, persistence, or sensitive file system access were identified in the reference files or instructions.
- Sanitization: There are no instructions for sanitizing or validating the content retrieved from external sources before it is processed for analysis.
Audit Metadata