balance-sheet-growth

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's documentation directs users to install and run the octagon-mcp package using npx to enable the required Model Context Protocol (MCP) server. This is a vendor-owned resource used for retrieving financial data.
  • [COMMAND_EXECUTION]: The setup guide provided in README.md and references/mcp-setup.md provides command-line instructions for setting environment variables and launching the MCP server. These instructions use standard practices for secret management by avoiding hardcoded API keys and instead recommending the use of environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external financial metrics, which presents a surface for indirect prompt injection if the retrieved data contains malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Financial growth metrics and balance sheet data retrieved via the octagon-agent tool described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or "ignore" instructions to separate the tool output from the system prompt.
  • Capability inventory: The skill's instructions are focused on analysis and text-based reporting; they do not include high-risk capabilities such as arbitrary file writing, network exfiltration, or secondary code execution based on the ingested content.
  • Sanitization: The skill lacks explicit sanitization or validation logic for the incoming data stream, relying on the expected structure of the financial reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — balance-sheet-growth