earnings-financial-guidance
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the Octagon MCP server using
npx octagon-mcpandoctagon-mcp@latest. These are official packages provided by the skill author (OctagonAI). - [REMOTE_CODE_EXECUTION]: The
mcp-setup.mdfile includes a command to install Homebrew via a piped bash script fetched from Homebrew's official GitHub repository. This is a standard and trusted installation method for development environments. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it processes external financial data.
- Ingestion points: The skill workflows in
SKILL.mdingest external data from<TICKER>'s latest earnings transcript. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions that might be embedded in the transcript text.
- Capability inventory: The skill performs its tasks using the
octagon-mcptool, which is restricted to extraction and analysis within the provided environment. - Sanitization: No specific filtering or sanitization of the transcript content is documented.
- Note: The risk remains minimal as the skill is focused on structured financial extraction and does not include capabilities for arbitrary command execution or writing to sensitive file paths.
Audit Metadata