sec-annual-comparison
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Octagon MCP server using
npx -y octagon-mcp@latest. This downloads and executes an external package from the npm registry to provide the market intelligence tools. - [EXTERNAL_DOWNLOADS]: The documentation in
references/mcp-setup.mdprovides the standard installation command for Homebrew, which involves downloading a shell script fromhttps://raw.githubusercontent.com/Homebrew/install/HEAD/install.shand executing it via bash. This is a well-known and standard setup procedure for macOS development environments. - [COMMAND_EXECUTION]: To configure the AI agent (e.g., Cursor, Claude Desktop), the skill requires executing local shell commands that set environment variables (
OCTAGON_API_KEY) and run thenpxcommand. These are manual configuration steps performed by the user to enable the MCP server's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes financial data retrieved from external sources (SEC filings) via the
octagon-agenttool. This is an inherent attack surface where instructions could theoretically be hidden in public disclosures to influence an AI's analysis. - Ingestion points: External SEC 10-K filings processed by the Octagon MCP server.
- Boundary markers: Not explicitly defined in the prompt instructions, though the skill provides a structured framework for data interpretation.
- Capability inventory: The skill facilitates analysis and visualization within the agent's context; it does not grant the external data source direct access to system commands or file-writing capabilities.
- Sanitization: Relies on the underlying AI model and the MCP server's internal processing to filter and structure the financial data before presentation.
Audit Metadata