earnings-call-insights

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation and setup guides reference downloading the octagon-mcp package via npx and an installation script for Homebrew. These are vendor-owned tools or well-known services provided for standard environment configuration.
  • [REMOTE_CODE_EXECUTION]: The documentation provides commands to execute a remote installation script from Homebrew's official GitHub repository and to run the octagon-mcp tool directly using npx. These are standard procedures for installing development tools and MCP servers from trusted or vendor sources.
  • [INDIRECT_PROMPT_INJECTION]: This skill is designed to ingest and analyze earnings call transcripts, which are external, untrusted inputs. This creates a potential surface where malicious instructions could be embedded in the transcript text to influence the AI's analysis. 1. Ingestion points: Transcripts are retrieved and processed via the Octagon MCP server as described in SKILL.md. 2. Boundary markers: The prompt templates in the skill instructions do not specify explicit delimiters or instructions for the agent to ignore commands found within the transcript data. 3. Capability inventory: The skill is scoped to text analysis and information extraction; it does not define capabilities for writing to the filesystem or making arbitrary network requests within the provided instruction files. 4. Sanitization: The instructions do not describe any sanitization or validation of the transcript content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:13 PM
Security Audit — agent-trust-hub — earnings-call-insights