esg-benchmark-comparison

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the Node.js environment using the official Homebrew installation script and the octagon-mcp tool from the NPM registry. These are standard procedures involving a well-known service and the vendor's own tool.
  • [REMOTE_CODE_EXECUTION]: Uses npx to execute the octagon-mcp package, which is necessary to run the tool that provides the ESG benchmarking functionality. The package is maintained by the skill author, OctagonAI.
  • [COMMAND_EXECUTION]: Includes documentation for configuring shell commands in IDEs like Cursor and Windsurf to pass environment variables (such as the API key) to the MCP server. This is the intended design for secure local configuration of the Model Context Protocol.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests benchmark data from external ESG frameworks. It mitigates potential confusion by providing extensive documentation in interpreting-results.md to guide the AI in correctly analyzing sector-specific and regional score variations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — esg-benchmark-comparison