trading-strategy
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions in
SKILL.mdspecifically direct the agent to ask the user for "headers/credentials" when they need to access paid sources like Substack or ZeroHedge. Collecting and handling these authentication secrets increases the risk of credential exposure if the agent's context is compromised or if secrets are logged. - [DYNAMIC_EXECUTION]: The skill provides patterns and templates for writing custom Python scripts at runtime. As seen in
references/research-patterns.md, the agent is encouraged to create scripts that perform network requests and data analysis, which are then executed within the agent's environment. - [PERSISTENCE]: The agent is instructed to use
schedule_taskto run monitoring scripts at regular intervals (e.g., "every 30 minutes"). This creates a persistence mechanism that allows code to execute repeatedly in the background across different sessions. - [COMMAND_EXECUTION]: The skill involves executing shell commands, specifically
python3 workspace/scripts/monitor.py, as part of its automated monitoring workflow. - [INDIRECT_PROMPT_INJECTION]: The skill has a high attack surface for indirect injection because it processes content from many external, untrusted sources.
- Ingestion points: The skill uses
web_fetchto retrieve article content,web_searchfor internet data, and tools liketwitter_search_tweetsandlunar_topicto ingest social media content. - Boundary markers: There are no instructions to use boundary markers or delimiters to isolate untrusted external content from the agent's internal instructions.
- Capability inventory: The agent has the capability to write files to the workspace, execute Python scripts, schedule persistent tasks, and make further outbound network requests.
- Sanitization: The instructions do not define any sanitization or validation protocols for the external data fetched, meaning instructions embedded in a web article or tweet could potentially influence the agent's behavior or script generation logic.
Audit Metadata