intelligent-investor-graham

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown-based instructions, checklists, and quote references. It does not include any scripts (.py, .js, .sh), executables, or configuration files that could trigger automated actions or command execution.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found. The skill operates within a strictly defined instructional framework for analyzing financial data based on provided 'knowledge source' quotes.
  • [EXTERNAL_DOWNLOADS]: The skill provides URLs for citations that point to the author's official GitHub repository. These are used for source-grounding and do not involve the download of executable content or sensitive data.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided financial data, it lacks the system-level capabilities (network access, file system modification, or command execution) necessary to facilitate a high-impact indirect prompt injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:52 AM
Security Audit — agent-trust-hub — intelligent-investor-graham