sec-footnotes-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Octagon MCP server using npx from the official NPM registry, which is a well-known service.
  • [EXTERNAL_DOWNLOADS]: The documentation references the official Homebrew installation script from GitHub to assist users with setting up the required Node.js environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from SEC filings. This represents a potential surface for indirect prompt injection where malicious instructions could be embedded in public filings; however, this is an inherent risk of the financial analysis use case and is mitigated by standard model guardrails.
  • [COMMAND_EXECUTION]: The workflow involves executing commands to set up the MCP server and invoking the octagon-agent tool. These operations are restricted to the intended purpose of the skill and utilize the author's own infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-footnotes-analysis