sec-corp-governance
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration instructions involve using
npxto run theoctagon-mcppackage. This is a standard mechanism for executing the MCP server required for the skill's functionality. The package is owned by the skill author (OctagonAI). - [COMMAND_EXECUTION]: The setup documentation provides commands for configuring MCP servers in various environments (Cursor, Claude Desktop, Windsurf). These commands involve setting environment variables and running the
octagon-mcputility, which is the intended behavior for this integration. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from SEC filings. While this represents a potential attack surface for indirect prompt injection from malicious filings, the skill's instructions focus on structured data analysis, and no specific vulnerabilities or bypasses were identified.
- [SAFE]: The documentation references the official Homebrew installation script from GitHub and standard Node.js installation procedures, which are legitimate developer workflows.
Audit Metadata