company-market-cap
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration and installation steps utilize
npxto download theoctagon-mcppackage from the public NPM registry. The setup documentation also references the official Homebrew installation script from GitHub. - [REMOTE_CODE_EXECUTION]: The skill is designed to run the
octagon-mcpserver vianpxto provide its core functionality. This involves executing code downloaded from a remote registry at runtime. - [COMMAND_EXECUTION]: The documentation provides command-line instructions for configuring the agent environment, including setting API keys via
envorsetand launching the MCP server. - [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface where it accepts ticker symbols and company names from user input and processes them through the
octagon-agenttool. Standard boundaries are recommended, but the nature of the tool requires processing external identifiers.
Audit Metadata