earnings-conf-call-sentiment

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation provides instructions to install and run the Octagon MCP server using npx. This is a vendor-owned resource provided by OctagonAI to enable the skill's functionality.
  • [REMOTE_CODE_EXECUTION]: The setup guide for macOS includes a command to install Homebrew by piping a script from its official GitHub repository directly into the shell (curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh | bash). This uses a well-known and established service for package management.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze earnings conference call transcripts, which are external data sources.
  • Ingestion points: Earnings conference call transcripts are retrieved and processed via the Octagon MCP tool as specified in the SKILL.md workflow.
  • Boundary markers: The prompt templates in the skill do not currently utilize specific markers or delimiters to isolate processed transcript content from the agent's core instructions.
  • Capability inventory: The skill uses the octagon-mcp tool for text analysis; it does not contain scripts with capabilities for arbitrary system modification, local file writing, or unauthorized network exfiltration.
  • Sanitization: There is no explicit evidence of content sanitization or instruction-filtering for the transcript data before it is processed by the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-conf-call-sentiment