income-statement-growth
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill requires the installation and execution of the
octagon-mcppackage vianpxto facilitate communication with the Octagon financial API. This is the intended operational model for the skill's infrastructure. - [EXTERNAL_DOWNLOADS]: The documentation provides setup instructions that include downloading the official Homebrew installation script from GitHub. This is a common and trusted method for configuring developer tools and runtimes like Node.js.
- [INDIRECT_PROMPT_INJECTION]: The skill processes financial data retrieved from the
octagon-agenttool. Since this data originates from external financial sources, it presents a theoretical surface for indirect prompt injection if those sources contain malicious instructions. - Ingestion points: Data returned by the
octagon-agenttool call inSKILL.md. - Boundary markers: None present; the skill treats the tool output as trusted financial data.
- Capability inventory: The agent has permissions to perform financial queries and provide analytical summaries to the user.
- Sanitization: The skill relies on the structured nature of financial reports and does not explicitly sanitize the text content for embedded instructions.
Audit Metadata