market-analyst-master

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The setup documentation includes instructions to install Node.js and Homebrew using standard scripts from trusted, well-known sources (e.g., raw.githubusercontent.com/Homebrew).
  • [COMMAND_EXECUTION]: The skill relies on the execution of the octagon-mcp package via npx, which is the intended mechanism for accessing the vendor's financial data tools.
  • [CREDENTIALS_SAFE]: The instructions follow security best practices by guiding users to provide their own API keys via environment variables rather than hardcoding credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process market data from an external API. While this creates a theoretical surface for indirect prompt injection, the risk is assessed as minimal due to the structured and numeric nature of the financial data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — market-analyst-master