sec-debt-covenant

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external data from public SEC filings (10-K, 10-Q, 8-K). This introduces a surface where malicious instructions embedded within a company's public disclosure could potentially influence the agent's behavior during analysis.
  • Ingestion points: SEC filing content retrieved and processed via the octagon-agent tool.
  • Boundary markers: There are no explicit instructions or delimiters defined to warn the agent to ignore potentially malicious content within the filings.
  • Capability inventory: The skill uses the octagon-agent tool, which has access to financial data agents and web search capabilities.
  • Sanitization: No specific content sanitization or validation steps are mentioned for the data ingested from SEC filings.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes setup instructions that download and execute code from external sources to prepare the environment.
  • Fetches the octagon-mcp package using npx from the npm registry.
  • References the official Homebrew installation script from its GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-debt-covenant