earnings-mgmt-comments

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration and setup instructions (README.md, references/mcp-setup.md) direct the user to download and execute the 'octagon-mcp' package using npx. This tool is provided by the skill's author, OctagonAI, to provide the necessary data extraction capabilities.
  • [EXTERNAL_DOWNLOADS]: In the macOS prerequisites section, the skill provides the official installation command for the Homebrew package manager, which involves downloading a shell script from GitHub and piping it directly to bash. This is a standard and well-recognized procedure for setting up developer environments on macOS.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted external data in the form of earnings call transcripts, which presents an attack surface for indirect prompt injection.
  • Ingestion points: External earnings call transcripts are ingested via the Octagon MCP server during the 'Extract Topic-Specific Commentary' workflow in SKILL.md.
  • Boundary markers: The provided prompt templates lack explicit boundary markers or instructions to the model to ignore any embedded directives within the transcript text.
  • Capability inventory: The skill instructions utilize the MCP server for data retrieval but do not explicitly call for dangerous capabilities like arbitrary shell execution or local file writes in the context of processing this data.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the transcript content before it is processed by the AI agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-mgmt-comments