trader-cloud-backtest
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied parameters such as strategy names, symbols, and date ranges and interpolates them directly into shell commands. * Ingestion points: User input for
<strategy-or-model>,<TICKER>, and<period>in SKILL.md. * Boundary markers: The skill does not use delimiters or instructions to ignore embedded commands within these inputs. * Capability inventory: The skill usesmanaged_agent_promptandBash, allowing for shell execution in the remote container. * Sanitization: There is no evidence of input validation or escaping before interpolation into themessagestring. - [COMMAND_EXECUTION]: The skill builds and dispatches shell commands (e.g.,
npx neural-trader --backtest --strategy <name> --symbol <TICKER>...) to a remote managed agent. An attacker providing malicious input for the strategy or symbol parameters could potentially execute arbitrary commands within the cloud-hosted environment. - [EXTERNAL_DOWNLOADS]: The skill automatically installs the
neural-traderpackage from the NPM registry during the container provisioning phase. The implementation follows security best practices by using the--ignore-scriptsflag to prevent the execution of potentially malicious lifecycle scripts during installation.
Audit Metadata