trader-portfolio-cg

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from the neural-trader CLI and results from AgentDB memory searches (Step 2). If these external sources were to provide malicious content, it could potentially influence the agent's behavior during subsequent Bash command execution or data storage steps.
  • Ingestion points: npx neural-trader output and mcp__plugin_ruflo-core_ruflo__memory_search results.
  • Boundary markers: None identified in the skill instructions to delimit external data from instructions.
  • Capability inventory: Bash execution for portfolio optimization fallbacks (Step 4) and mcp__plugin_ruflo-core_ruflo__memory_store for persistent storage of results.
  • Sanitization: No explicit validation or sanitization of the ingested data is described before it is processed or stored.
  • [EXTERNAL_DOWNLOADS]: The skill performs runtime installation of the neural-trader package using npm (Step 1). While the use of --ignore-scripts mitigates the risk of malicious post-installation scripts, fetching packages at runtime introduces a dependency on the integrity of the external package registry.
  • [COMMAND_EXECUTION]: The skill relies on the Bash tool to execute multiple shell commands, including package management commands (npm install) and external CLI utilities (npx neural-trader).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — trader-portfolio-cg