company-market-cap

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration and installation steps utilize npx to download the octagon-mcp package from the public NPM registry. The setup documentation also references the official Homebrew installation script from GitHub.
  • [REMOTE_CODE_EXECUTION]: The skill is designed to run the octagon-mcp server via npx to provide its core functionality. This involves executing code downloaded from a remote registry at runtime.
  • [COMMAND_EXECUTION]: The documentation provides command-line instructions for configuring the agent environment, including setting API keys via env or set and launching the MCP server.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface where it accepts ticker symbols and company names from user input and processes them through the octagon-agent tool. Standard boundaries are recommended, but the nature of the tool requires processing external identifiers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — company-market-cap