risk-manager

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of natural language instructions and domain-specific guidance for risk management tasks. There are no scripts, binaries, or command-line instructions provided within the skill content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external portfolio data and trade logs, which creates a theoretical surface for indirect prompt injection. However, the skill lacks any dangerous capabilities (such as network access, file system modifications, or command execution) that could be leveraged if malicious instructions were encountered in the input data.
  • Ingestion points: Processes user-provided portfolio metrics and trade history via prompts.
  • Boundary markers: None explicitly defined within the skill text.
  • Capability inventory: None. No file-writing, network, or subprocess capabilities are utilized.
  • Sanitization: Not applicable as the output is restricted to textual analysis and reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:55 AM
Security Audit — agent-trust-hub — risk-manager