trader-risk
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
neural-traderpackage from the NPM registry usingnpm install. It follows security best practices by including the--ignore-scriptsflag, which prevents the execution of arbitrary lifecycle scripts during the installation process. - [COMMAND_EXECUTION]: The skill uses
npxto execute commands from theneural-traderpackage to perform risk assessments, calculate Value at Risk (VaR), and check circuit breaker statuses. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data which could lead to instruction injection if the inputs are not properly sanitized.
- Ingestion points: The skill accepts external input through the
--symbol(TICKER) and--portfolio(NAME) arguments inSKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat these interpolated variables as untrusted data.
- Capability inventory: The skill possesses the capability to execute shell commands via the
Bashtool to runnpmandnpxoperations. - Sanitization: The instructions do not define any validation, escaping, or filtering logic for the ticker symbols or portfolio names before they are passed to the shell environment.
Audit Metadata