earnings-qa-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation directs the user to install and execute the octagon-mcp package using npx, bunx, or pnpm. This package is a core component provided by the author, OctagonAI, to facilitate the intended transcript analysis.
  • [COMMAND_EXECUTION]: Setup instructions include standard shell commands for environment preparation, such as installing Node.js and Homebrew from official repositories, and configuring MCP server instances within AI agents using environment variables for API key management.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process earnings call transcripts, which are external data sources. While this represents a potential injection surface, the risk is inherent to the data analysis use case and is considered low given the specialized nature of the content.
  • Ingestion points: Earnings call transcripts (referenced in SKILL.md and README.md).
  • Boundary markers: No explicit delimiter-based sanitization is described in the prompt templates.
  • Capability inventory: The skill uses the octagon-mcp tool for structured analysis and insights extraction.
  • Sanitization: Not explicitly defined; the skill relies on the underlying LLM's safety tuning and the specialized MCP server's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — earnings-qa-analysis