cash-flow-growth
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installation and setup process involves downloading packages from the npm registry (
npx -y octagon-mcp). These packages are managed by the skill author (OctagonAI) and are used to provide the financial data backend. - [COMMAND_EXECUTION]: The documentation provides standard setup instructions for MCP servers in AI agents (Cursor, Claude Desktop), which include executing shell commands with environment variables for API key management. This is consistent with established practices for the OctagonAI platform.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a consumer of external financial data provided by the
octagon-agenttool. This ingestion of external data to generate observations creates a theoretical attack surface for indirect prompt injection if the data source were compromised, though it is currently within a trusted vendor-managed environment. - Ingestion points: Data returned from the
octagon-mcptool is used as the basis for generating observations (SKILL.md). - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing the financial data.
- Capability inventory: The skill is primarily read-only, generating analytical text and suggested follow-up queries based on the data.
- Sanitization: The instructions do not specify sanitization or escaping logic for the retrieved financial metrics.
Audit Metadata