skills/octagonai/skills/stock-grades/Gen Agent Trust Hub

stock-grades

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install and run the 'octagon-mcp' tool using the Node package runner (npx). This tool is provided by the skill author (OctagonAI) and is part of the required infrastructure for the skill to function.
  • [EXTERNAL_DOWNLOADS]: Installation steps for prerequisites include a command to download and execute the Homebrew installation script from its official GitHub repository ('raw.githubusercontent.com/Homebrew/install/HEAD/install.sh'). This targets a well-known and trusted service.
  • [COMMAND_EXECUTION]: The setup guide includes commands for users to configure their environment, such as setting the 'OCTAGON_API_KEY' and launching the MCP server. These are standard configuration procedures for the platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external financial data (analyst ratings and institutional sentiment) which could theoretically contain malicious instructions if the upstream data source were compromised.
  • Ingestion points: Analyst ratings, institution names, and historical rating data retrieved from the Octagon API via the 'octagon-agent' tool.
  • Boundary markers: None explicitly defined in the instructions to the agent.
  • Capability inventory: The skill uses specific MCP tools ('octagon-agent', 'octagon-scraper-agent') for market intelligence gathering.
  • Sanitization: The skill assumes the integrity of the financial data provided by the Octagon platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — stock-grades