analyst-estimates

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes financial metrics from external sources, which constitutes a surface where malicious instructions could theoretically be embedded in the retrieved data to influence agent behavior.\n
  • Ingestion points: External financial data and analyst coverage metrics retrieved through the octagon-agent tool.\n
  • Boundary markers: The skill templates do not utilize explicit delimiters or markers to separate untrusted data from the agent's internal instructions.\n
  • Capability inventory: The agent uses ingested data to perform calculations including CAGR, Forward P/E, and PEG ratios.\n
  • Sanitization: No specific filtering or sanitization of external strings is documented before the analysis phase.\n- [EXTERNAL_DOWNLOADS]: Setup and installation documentation provided with the skill involves downloading external code and configuration scripts.\n
  • Evidence: The references/mcp-setup.md file contains instructions for installing Homebrew using a curl | bash command and running the octagon-mcp server via npx.\n
  • Context: These resources are hosted by well-known services or the vendor's own official channels for legitimate setup purposes and do not indicate malicious behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — analyst-estimates