investment-research

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of markdown instructions and configuration files. It does not include any code, external dependencies, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external documents such as SEC filings and earnings call transcripts, which constitutes an ingestion surface for indirect prompt injection. However, this risk is categorized as safe because the skill has no active capabilities (e.g., shell access, network operations) that could be leveraged by a malicious payload embedded in the financial data.
  • Ingestion points: SEC filings (Form 10-K, Form 10-Q) and executive earnings call transcripts (identified in SKILL.md).
  • Boundary markers: Absent; the instructions do not suggest using delimiters to isolate external data from agent instructions.
  • Capability inventory: None; the skill does not invoke any tools, scripts, or network functions.
  • Sanitization: Absent; there are no instructions to sanitize or validate the content of the analyzed documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 04:25 AM
Security Audit — agent-trust-hub — investment-research