stock-historical-index
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install Node.js and Homebrew using standard scripts from trusted organizations' GitHub repositories. It also utilizes
npxto fetch and run vendor-provided packages. - [COMMAND_EXECUTION]: Configuration guides for various AI agents (Cursor, Claude Desktop, Windsurf) involve setting up environment variables and running shell commands via
npxto initialize the Octagon MCP server. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret market data retrieved from an external API, which presents a potential injection surface if the external data source were compromised.
- Ingestion points: Data retrieved from the
octagon-agenttool as described inSKILL.md. - Boundary markers: None explicitly defined in the prompt instructions provided to the agent.
- Capability inventory: The skill uses the
octagon-agenttool to fetch market data; the skill itself does not perform direct file system or network operations outside of the tool call. - Sanitization: No specific sanitization or filtering of the retrieved market data is mentioned before it is processed by the agent.
Audit Metadata