trading-strategy

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions in SKILL.md specifically direct the agent to ask the user for "headers/credentials" when they need to access paid sources like Substack or ZeroHedge. Collecting and handling these authentication secrets increases the risk of credential exposure if the agent's context is compromised or if secrets are logged.
  • [DYNAMIC_EXECUTION]: The skill provides patterns and templates for writing custom Python scripts at runtime. As seen in references/research-patterns.md, the agent is encouraged to create scripts that perform network requests and data analysis, which are then executed within the agent's environment.
  • [PERSISTENCE]: The agent is instructed to use schedule_task to run monitoring scripts at regular intervals (e.g., "every 30 minutes"). This creates a persistence mechanism that allows code to execute repeatedly in the background across different sessions.
  • [COMMAND_EXECUTION]: The skill involves executing shell commands, specifically python3 workspace/scripts/monitor.py, as part of its automated monitoring workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a high attack surface for indirect injection because it processes content from many external, untrusted sources.
  • Ingestion points: The skill uses web_fetch to retrieve article content, web_search for internet data, and tools like twitter_search_tweets and lunar_topic to ingest social media content.
  • Boundary markers: There are no instructions to use boundary markers or delimiters to isolate untrusted external content from the agent's internal instructions.
  • Capability inventory: The agent has the capability to write files to the workspace, execute Python scripts, schedule persistent tasks, and make further outbound network requests.
  • Sanitization: The instructions do not define any sanitization or validation protocols for the external data fetched, meaning instructions embedded in a web article or tweet could potentially influence the agent's behavior or script generation logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — trading-strategy