balance-sheet-growth
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's documentation directs users to install and run the
octagon-mcppackage usingnpxto enable the required Model Context Protocol (MCP) server. This is a vendor-owned resource used for retrieving financial data. - [COMMAND_EXECUTION]: The setup guide provided in
README.mdandreferences/mcp-setup.mdprovides command-line instructions for setting environment variables and launching the MCP server. These instructions use standard practices for secret management by avoiding hardcoded API keys and instead recommending the use of environment variables. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external financial metrics, which presents a surface for indirect prompt injection if the retrieved data contains malicious instructions intended to influence the agent's behavior.
- Ingestion points: Financial growth metrics and balance sheet data retrieved via the
octagon-agenttool described inSKILL.md. - Boundary markers: The skill does not define specific delimiters or "ignore" instructions to separate the tool output from the system prompt.
- Capability inventory: The skill's instructions are focused on analysis and text-based reporting; they do not include high-risk capabilities such as arbitrary file writing, network exfiltration, or secondary code execution based on the ingested content.
- Sanitization: The skill lacks explicit sanitization or validation logic for the incoming data stream, relying on the expected structure of the financial reports.
Audit Metadata