earnings-cost-mgmt

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the octagon-mcp package from the npm registry. This is a vendor-provided dependency necessary for interacting with the earnings transcript API.
  • [REMOTE_CODE_EXECUTION]: The setup guide in references/mcp-setup.md includes the official installation command for Homebrew, which executes a remote script via /bin/bash. This is a standard procedure for a well-known developer tool.
  • [COMMAND_EXECUTION]: The MCP server configuration requires executing shell commands with environment variables to provide the API key, as detailed in the setup instructions for various IDEs.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a consumer for external data by analyzing earnings transcripts, which serves as an ingestion point for untrusted content.
  • Ingestion points: Earnings transcripts parsed in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are used in the prompt templates.
  • Capability inventory: The skill is limited to data analysis and extraction through the provided MCP tool.
  • Sanitization: No sanitization mechanisms are described for the processed text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-cost-mgmt