sec-segment-reporting
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to install and run the 'octagon-mcp' package and 'skills' CLI tool via npx/bunx/pnpm. These are official vendor resources provided by OctagonAI. Additionally, the setup guide provides instructions for installing Homebrew, a well-known package manager.
- [COMMAND_EXECUTION]: The documentation includes shell commands for environment configuration and tool startup, such as 'npx -y octagon-mcp'. The use of the '-y' flag skips confirmation prompts for package installation.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and analysis of external SEC filings, which represents a potential surface for indirect prompt injection if the filings were to contain adversarial instructions.
- Ingestion points: The 'octagon-agent' tool is used to retrieve and process the content of 10-K and 10-Q filings from the SEC based on company tickers provided in the prompt.
- Boundary markers: No explicit delimiters or instructions to ignore embedded instructions within the filing content are identified.
- Capability inventory: The skill leverages 'octagon-agent' and 'octagon-sec-agent' for data synthesis and financial research.
- Sanitization: The instruction files do not define any specific sanitization or filtering protocols for the external data ingested from SEC filings.
Audit Metadata