portfolio-monitor

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements legitimate financial monitoring logic, including structures for KPI tracking and return analysis (IRR, MOIC).
  • [SAFE]: References to FactSet, S&P Global, and PitchBook MCP servers involve well-known and reputable technology services.
  • [SAFE]: The persona description references Anthropic's financial services as an inspiration, which is a trusted organization.
  • [SAFE]: The use of exclamation marks at the end of section headers (e.g., 'Implementation:!') appears to be a stylistic instructional choice and does not match the syntax for dynamic context injection or obfuscation.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface (Category 8) due to its data processing nature.
  • Ingestion points: The skill ingests untrusted financial data (KPIs, variances, and returns) from the user into the agent's context in SKILL.md.
  • Boundary markers: Absent. There are no explicit delimiters or instructions provided to the agent to ignore embedded commands within the processed data.
  • Capability inventory: The skill generates detailed portfolio reports and performs asset comparison.
  • Sanitization: Absent. No validation or sanitization is performed on the financial data before it is incorporated into the reporting template.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 08:38 PM
Security Audit — agent-trust-hub — portfolio-monitor