stock-grades
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install and run the 'octagon-mcp' tool using the Node package runner (npx). This tool is provided by the skill author (OctagonAI) and is part of the required infrastructure for the skill to function.
- [EXTERNAL_DOWNLOADS]: Installation steps for prerequisites include a command to download and execute the Homebrew installation script from its official GitHub repository ('raw.githubusercontent.com/Homebrew/install/HEAD/install.sh'). This targets a well-known and trusted service.
- [COMMAND_EXECUTION]: The setup guide includes commands for users to configure their environment, such as setting the 'OCTAGON_API_KEY' and launching the MCP server. These are standard configuration procedures for the platform.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external financial data (analyst ratings and institutional sentiment) which could theoretically contain malicious instructions if the upstream data source were compromised.
- Ingestion points: Analyst ratings, institution names, and historical rating data retrieved from the Octagon API via the 'octagon-agent' tool.
- Boundary markers: None explicitly defined in the instructions to the agent.
- Capability inventory: The skill uses specific MCP tools ('octagon-agent', 'octagon-scraper-agent') for market intelligence gathering.
- Sanitization: The skill assumes the integrity of the financial data provided by the Octagon platform.
Audit Metadata