earnings-analyst-master

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the Homebrew installation script from its official GitHub repository to set up the necessary environment on macOS.
  • [COMMAND_EXECUTION]: Uses the npx command to run the vendor's octagon-mcp package, which is the standard method for interacting with Octagon's financial analysis tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external earnings call transcripts, which introduces a surface for indirect prompt injection if those transcripts were to contain malicious instructions.
  • Ingestion points: Earnings call transcripts accessed via MCP tools (SKILL.md).
  • Boundary markers: No explicit boundary markers or "ignore instructions" warnings are defined in the prompt templates to distinguish between analysis instructions and transcript content.
  • Capability inventory: The skill has the ability to access market intelligence, transcript data, and perform web research via integrated tools (references/mcp-setup.md).
  • Sanitization: There is no mention of sanitization or filtering for the external transcript data before it is processed by the AI.
  • [PRIVILEGE_ESCALATION]: The setup instructions for Homebrew and Node.js on macOS may require the use of sudo or similar elevated permissions to complete the system-level installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:17 AM
Security Audit — agent-trust-hub — earnings-analyst-master