sec-mda-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration involves downloading the octagon-mcp tool from the NPM registry via npx. This package is owned and maintained by the vendor (OctagonAI).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external SEC filings for analysis. While this presents an ingestion point for untrusted data, the risk is minimal as the skill's instructions are focused on data extraction and summarization without high-privilege execution capabilities.
  • [CREDENTIALS_SAFE]: Instructions for setting up the OCTAGON_API_KEY follow standard security practices, utilizing environment variables and local configuration files rather than hardcoding secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-mda-analysis