earnings-call-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation guides the user to install the octagon-mcp package via npx to provide the necessary tools for transcript analysis.
  • [COMMAND_EXECUTION]: The setup process involves configuring the AI agent to execute shell commands using npx to launch the MCP server with environment variables.
  • [REMOTE_CODE_EXECUTION]: The setup guide for macOS includes a command to install Homebrew by piping a remote script from a well-known repository into bash, which is a standard installation practice for that service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes earnings call transcripts from external sources, which could potentially contain malicious instructions designed to influence the AI's behavior during analysis.
  • Ingestion points: Earnings call transcripts processed in SKILL.md via MCP tools.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the transcript text.
  • Capability inventory: The skill extracts insights, financial metrics, and generates follow-up questions based on the input text.
  • Sanitization: No content filtering or sanitization steps for the transcript data are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:13 PM
Security Audit — agent-trust-hub — earnings-call-analysis