sec-footnotes-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Octagon MCP server using
npxfrom the official NPM registry, which is a well-known service. - [EXTERNAL_DOWNLOADS]: The documentation references the official Homebrew installation script from GitHub to assist users with setting up the required Node.js environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from SEC filings. This represents a potential surface for indirect prompt injection where malicious instructions could be embedded in public filings; however, this is an inherent risk of the financial analysis use case and is mitigated by standard model guardrails.
- [COMMAND_EXECUTION]: The workflow involves executing commands to set up the MCP server and invoking the
octagon-agenttool. These operations are restricted to the intended purpose of the skill and utilize the author's own infrastructure.
Audit Metadata