historical-market-cap

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The setup documentation provides standard installation procedures for Homebrew and Node.js from their respective official and well-known sources.
  • [REMOTE_CODE_EXECUTION]: The skill instructions guide users to configure and run the octagon-mcp tool using npx, which is the standard execution method for the vendor's MCP server.
  • [COMMAND_EXECUTION]: The configuration steps involve setting environment variables for API keys and executing shell commands to initialize the MCP server within the AI agent environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes historical financial data retrieved from external sources. While this data is interpolated into the agent's context for analysis (such as calculating growth trends and Identifying peaks), the surface is restricted to structured financial metrics.
  • [CREDENTIALS_UNSAFE]: The documentation correctly identifies the use of environment variables for API key management and provides placeholders (YOUR_API_KEY_HERE, <your-api-key>) instead of hardcoding sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — historical-market-cap