commodities-list

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's setup instructions involve downloading the octagon-mcp package from the npm registry and the Homebrew installation script. Both are from reputable or vendor-controlled sources and are necessary for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses tools to process natural language queries about commodity markets. While it lacks explicit boundary markers for untrusted data, this is consistent with its intended use as a research aid and the data sources are controlled.
  • [COMMAND_EXECUTION]: Configuration steps involve executing shell commands to set environment variables and initialize the MCP server, which is standard practice for this type of integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:13 PM
Security Audit — agent-trust-hub — commodities-list