cash-flow-statement

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external financial data from the octagon-financials-agent, which introduces a potential surface for indirect prompt injection if the source data contains malicious instructions.
  • Ingestion points: Untrusted data enters the agent context via the octagon-agent tool as specified in SKILL.md.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are provided in the prompt templates to isolate external data from instructions.
  • Capability inventory: The agent has access to the octagon-agent tool, which can execute further market intelligence and data extraction tasks.
  • Sanitization: There is no evidence of content filtering or sanitization for the retrieved financial data.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/mcp-setup.md provides instructions to install Homebrew using a remote script execution pattern (curl | bash). This targets the official repository of the Homebrew project, which is a well-known service.
  • [COMMAND_EXECUTION]: The skill setup requires executing the octagon-mcp server using npx. This is the standard execution method for the vendor's MCP tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — cash-flow-statement