sec-10q-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Homebrew installation script from its official repository on GitHub to set up Node.js prerequisites on macOS.
  • [COMMAND_EXECUTION]: Executes the Homebrew installation script via /bin/bash and utilizes npx to run the vendor's own octagon-mcp server. These are standard operations for the skill's setup and functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external SEC 10-Q filings, which are untrusted external sources.
  • Ingestion points: Quarterly financial filings processed through the octagon-agent tool.
  • Boundary markers: None explicitly defined; the skill uses natural language prompting for extraction.
  • Capability inventory: Data extraction and performance metrics analysis.
  • Sanitization: Relies on the agent's internal logic and the structured nature of regulatory filings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-10q-analysis