revenue-geographic-segmentation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The setup documentation (
references/mcp-setup.md) provides instructions to install the Homebrew package manager using a remote script from GitHub (https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh). This is a standard and well-recognized installation procedure for macOS development environments. - [COMMAND_EXECUTION]: The skill provides instructions for configuring the AI agent with the
octagon-mcpserver usingnpx. This command executes theoctagon-mcppackage, which is a legitimate tool provided by the skill's author (octagonai). - [INDIRECT_PROMPT_INJECTION]: The skill processes financial data retrieved from the
octagon-agenttool, which presents an inherent injection surface if the source data were maliciously crafted. - Ingestion points: Data retrieved from the
octagon-agentMCP tool referenced inSKILL.md. - Boundary markers: The skill uses markdown table structures to organize output but does not explicitly define boundary markers to isolate data from instructions.
- Capability inventory: The skill instructions focus on data retrieval and analysis; no evidence of high-risk capabilities like file system writes or unauthorized network operations was found in the skill files.
- Sanitization: No explicit sanitization or validation of the tool output is defined within the skill's prompts.
Audit Metadata