earnings-financial-guidance

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the Octagon MCP server using npx octagon-mcp and octagon-mcp@latest. These are official packages provided by the skill author (OctagonAI).
  • [REMOTE_CODE_EXECUTION]: The mcp-setup.md file includes a command to install Homebrew via a piped bash script fetched from Homebrew's official GitHub repository. This is a standard and trusted installation method for development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it processes external financial data.
  • Ingestion points: The skill workflows in SKILL.md ingest external data from <TICKER>'s latest earnings transcript.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions that might be embedded in the transcript text.
  • Capability inventory: The skill performs its tasks using the octagon-mcp tool, which is restricted to extraction and analysis within the provided environment.
  • Sanitization: No specific filtering or sanitization of the transcript content is documented.
  • Note: The risk remains minimal as the skill is focused on structured financial extraction and does not include capabilities for arbitrary command execution or writing to sensitive file paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-financial-guidance