income-statement

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's setup documentation provides instructions to install the Octagon MCP server via npx and references the official Homebrew installation script. These resources originate from the skill's vendor or well-known, trusted services.
  • [COMMAND_EXECUTION]: The installation and configuration process involves executing shell commands to manage environment variables and initialize the MCP server using tools like npx, npm, and node.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests financial data from an external API, which creates a potential surface for indirect prompt injection as the instructions do not implement specific boundary markers or data validation for the tool output.
  • Ingestion points: Data retrieved from the octagon-agent tool as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or provide the agent with guidance to ignore instructions potentially embedded in the tool's output.
  • Capability inventory: The skill utilizes the octagon-mcp server tools for data retrieval, which are then used by the agent to perform financial analysis.
  • Sanitization: There is no mention of sanitizing or validating the contents of the API response before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:13 PM
Security Audit — agent-trust-hub — income-statement