sec-proxy-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and execution of the octagon-mcp package from the Node package registry via npx. This is a vendor-owned resource provided by OctagonAI for the skill's primary functionality.- [COMMAND_EXECUTION]: Setup instructions include the official Homebrew installation command, which retrieves a shell script from the Homebrew GitHub repository. Homebrew and GitHub are recognized as well-known and trusted services, and the command is standard for setting up a development environment on macOS.- [INDIRECT_PROMPT_INJECTION]: The skill processes SEC proxy statements (DEF 14A filings) through the octagon-agent tool. As these are external documents, they represent an indirect prompt injection surface. The skill manages this risk by providing the agent with highly structured extraction workflows that focus on specific financial and governance data points, reducing the likelihood of accidental instruction following from document text. Ingestion points include the SEC filing data; no specific boundary markers are defined for the input content; capabilities are limited to the authorized MCP tools; and sanitization is handled by the underlying market intelligence agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — sec-proxy-analysis