financial-growth

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the octagon-mcp package from the npm registry and the Homebrew package manager from its official repository. These are standard procedures for configuring the necessary execution environment.
  • Evidence: npx -y octagon-mcp@latest in references/mcp-setup.md and README.md.
  • Evidence: https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh in references/mcp-setup.md.
  • [REMOTE_CODE_EXECUTION]: The setup guide includes the official Homebrew installation command which downloads and executes a script from GitHub. This is a common and accepted method for installing developer software on macOS.
  • Evidence: /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" in references/mcp-setup.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input, such as stock tickers and record counts, and interpolates them into a natural language prompt string passed to the octagon-agent tool. This pattern represents a surface for potential injection, though its impact is limited by the tool's specialized financial scope.
  • Ingestion points: User-supplied <TICKER>, <N> records, and <FY|Q> period in SKILL.md.
  • Boundary markers: None; the input is directly embedded into the text prompt for the MCP agent.
  • Capability inventory: The skill calls the octagon-agent tool to retrieve market intelligence and financial data.
  • Sanitization: No explicit validation or filtering of the user-provided variables is documented within the instruction files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — financial-growth