earnings-cost-mgmt
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the
octagon-mcppackage from the npm registry. This is a vendor-provided dependency necessary for interacting with the earnings transcript API. - [REMOTE_CODE_EXECUTION]: The setup guide in
references/mcp-setup.mdincludes the official installation command for Homebrew, which executes a remote script via/bin/bash. This is a standard procedure for a well-known developer tool. - [COMMAND_EXECUTION]: The MCP server configuration requires executing shell commands with environment variables to provide the API key, as detailed in the setup instructions for various IDEs.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a consumer for external data by analyzing earnings transcripts, which serves as an ingestion point for untrusted content.
- Ingestion points: Earnings transcripts parsed in
SKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded content are used in the prompt templates.
- Capability inventory: The skill is limited to data analysis and extraction through the provided MCP tool.
- Sanitization: No sanitization mechanisms are described for the processed text.
Audit Metadata