earnings-product-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses environment variables (
OCTAGON_API_KEY) to manage user credentials during MCP server configuration, which is a standard security best practice that avoids hardcoding secrets. - [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the Homebrew package manager using the official installation script from Homebrew's GitHub repository, which is a well-known and trusted source.
- [REMOTE_CODE_EXECUTION]: The skill relies on
npxto runoctagon-mcp, which is the official tool provided by the vendor (OctagonAI) for this skill's functionality. This is the intended deployment mechanism for this ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external earnings call transcripts, which could potentially contain adversarial content intended to influence the LLM's output.
- Ingestion points: Earnings call transcripts referenced via ticker symbols in
SKILL.md. - Boundary markers: The prompt instructions in
SKILL.mddo not currently specify boundary markers or delimiters for the transcript data. - Capability inventory: The skill utilizes the
Octagon MCPserver for data analysis. - Sanitization: No specific data sanitization or filtering logic is defined for the input transcripts.
Audit Metadata