sec-business-desc-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to download and execute the
octagon-mcptool from the NPM registry usingnpx. This is a vendor-owned package from OctagonAI. - [REMOTE_CODE_EXECUTION]: Setup instructions for macOS recommend installing Homebrew using a remote shell script (
raw.githubusercontent.com/Homebrew/install/HEAD/install.sh) which is then executed in the shell. This is a standard installation method for a well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill processes Item 1 Business sections from SEC filings, which are external data sources that could contain malicious instructions.
- Ingestion points: Company 10-K filings are retrieved via the
octagon-agenttool. - Boundary markers: The instructions lack explicit delimiters or warnings for the agent to ignore embedded instructions within the filings.
- Capability inventory: The skill uses the
octagon-agenttool to summarize and analyze business models and competitive landscapes. - Sanitization: There is no documentation of sanitization or filtering being applied to the retrieved SEC content before it enters the agent's context.
Audit Metadata