sec-10k-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill and its referenced tools (octagon-mcp, octagon-agent) originate from the verified author, OctagonAI. All external links point to legitimate vendor domains including octagonai.co, octagonagents.com, and the official GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external SEC 10-K filings, which constitutes an ingestion surface for third-party data.
  • Ingestion points: Financial documents are retrieved and processed via the octagon-agent tool as specified in SKILL.md.
  • Boundary markers: The instructions do not explicitly define delimiters to separate filing text from the agent's internal instructions.
  • Capability inventory: The skill is scoped to data extraction, summarization, and analysis of financial metrics.
  • Sanitization: Input validation and sanitization are handled by the underlying octagon-mcp server implementation.
  • [EXTERNAL_DOWNLOADS]: The setup documentation in references/mcp-setup.md provides instructions for installing standard developer prerequisites from trusted sources.
  • Evidence: Includes the official installation command for Homebrew (raw.githubusercontent.com/Homebrew).
  • [REMOTE_CODE_EXECUTION]: The configuration steps for Cursor and Claude Desktop involve executing the octagon-mcp package via npx.
  • Evidence: Command instructions utilize 'npx -y octagon-mcp' to fetch and run the vendor's MCP server. This is a standard integration method for the Model Context Protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-10k-analysis