initiating-coverage

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • Local Script Execution: The skill incorporates several Python scripts located in the scripts/ directory for tasks such as JSON validation, Markdown generation, and financial math calculations. These scripts operate deterministically on local data and do not exhibit suspicious behaviors such as network communication or unauthorized file system access.
  • External Data Ingestion Considerations: The skill is designed to process external financial data, including company filings, transcripts, and presentations. While this introduces a standard surface for potential indirect prompt injection (e.g., if instructions were embedded in a financial transcript), the skill implements a structured source and evidence protocol. This protocol requires the agent to label information as 'fact', 'company_claim', or 'assumption', which helps maintain context and serves as a security best practice for managing untrusted data.
  • Controlled Environment Operations: The instructions involve executing an internal preflight script and utilizing local headless-browser screenshots for QA. These operations are conducted within the local working environment and are consistent with the skill's stated purpose of professional research and reporting.
  • Data Integrity and Preservation: The skill includes explicit instructions to preserve existing user files and models, directing the agent to create additive or marked-up recommendations rather than overwriting original materials, which supports data safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:12 AM
Security Audit — agent-trust-hub — initiating-coverage