stock-historical-index

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install Node.js and Homebrew using standard scripts from trusted organizations' GitHub repositories. It also utilizes npx to fetch and run vendor-provided packages.
  • [COMMAND_EXECUTION]: Configuration guides for various AI agents (Cursor, Claude Desktop, Windsurf) involve setting up environment variables and running shell commands via npx to initialize the Octagon MCP server.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret market data retrieved from an external API, which presents a potential injection surface if the external data source were compromised.
  • Ingestion points: Data retrieved from the octagon-agent tool as described in SKILL.md.
  • Boundary markers: None explicitly defined in the prompt instructions provided to the agent.
  • Capability inventory: The skill uses the octagon-agent tool to fetch market data; the skill itself does not perform direct file system or network operations outside of the tool call.
  • Sanitization: No specific sanitization or filtering of the retrieved market data is mentioned before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 PM
Security Audit — agent-trust-hub — stock-historical-index