sec-corp-governance

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration instructions involve using npx to run the octagon-mcp package. This is a standard mechanism for executing the MCP server required for the skill's functionality. The package is owned by the skill author (OctagonAI).
  • [COMMAND_EXECUTION]: The setup documentation provides commands for configuring MCP servers in various environments (Cursor, Claude Desktop, Windsurf). These commands involve setting environment variables and running the octagon-mcp utility, which is the intended behavior for this integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from SEC filings. While this represents a potential attack surface for indirect prompt injection from malicious filings, the skill's instructions focus on structured data analysis, and no specific vulnerabilities or bypasses were identified.
  • [SAFE]: The documentation references the official Homebrew installation script from GitHub and standard Node.js installation procedures, which are legitimate developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-corp-governance