financial-analyst-master

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large amounts of external data, including SEC filings, earnings call transcripts, and financial news, which creates a surface for indirect prompt injection.
  • Ingestion points: External data is fetched using the octagon-agent, octagon-scraper-agent, and octagon-deep-research-agent tools referenced in the analysis workflow.
  • Boundary markers: The instructions do not specify the use of delimiters (such as XML tags or triple quotes) or specific "ignore embedded instructions" warnings when processing this external content.
  • Capability inventory: The skill has the capability to generate long-form institutional research reports and perform network operations via the integrated MCP tools.
  • Sanitization: There is no mention of sanitizing, escaping, or filtering the ingested external content before it is interpolated into the agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill instructions guide the user to download and run vendor-provided tools and well-known configuration scripts.
  • Fetches the octagon-mcp package from the registry using npx during the setup phase.
  • References the official Homebrew installation script for macOS environment preparation.
  • [REMOTE_CODE_EXECUTION]: The setup documentation for Mac environments includes a command to fetch and execute a script from a well-known service.
  • Includes the standard Homebrew installation command: curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh | bash.
  • [COMMAND_EXECUTION]: The skill's setup documentation provides shell commands for configuring the MCP server, setting environment variables, and verifying the installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — financial-analyst-master