earnings-analyst-questions

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the octagon-mcp package via npx. This is an official component from the vendor (OctagonAI) used to fetch and process financial transcripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external earnings call transcripts, which constitutes a vulnerability surface.
  • Ingestion points: Transcripts are accessed through the Octagon MCP server as outlined in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from following commands that might be embedded in transcript text.
  • Capability inventory: The skill is restricted to data extraction, thematic analysis, and attribution; it does not provide capabilities for file system modification or outbound network requests.
  • Sanitization: No explicit sanitization or content validation is implemented within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-analyst-questions