skills/ruvnet/ruflo/trader-risk/Gen Agent Trust Hub

trader-risk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the neural-trader package from the NPM registry using npm install. It follows security best practices by including the --ignore-scripts flag, which prevents the execution of arbitrary lifecycle scripts during the installation process.
  • [COMMAND_EXECUTION]: The skill uses npx to execute commands from the neural-trader package to perform risk assessments, calculate Value at Risk (VaR), and check circuit breaker statuses.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data which could lead to instruction injection if the inputs are not properly sanitized.
  • Ingestion points: The skill accepts external input through the --symbol (TICKER) and --portfolio (NAME) arguments in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat these interpolated variables as untrusted data.
  • Capability inventory: The skill possesses the capability to execute shell commands via the Bash tool to run npm and npx operations.
  • Sanitization: The instructions do not define any validation, escaping, or filtering logic for the ticker symbols or portfolio names before they are passed to the shell environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — trader-risk