market-research

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves deep web research and data collection from external reports and earnings calls (SKILL.md, Phase 1). This creates a vulnerability where instructions embedded in processed external content could influence the agent's behavior, as the skill lacks explicit safeguards.
  • Ingestion points: Phase 1: Research (SKILL.md) explicitly instructs the agent to perform deep web research for market data, reports, and earnings calls.
  • Boundary markers: The instructions do not define delimiters or provide "ignore embedded instructions" warnings for the agent when processing external data.
  • Capability inventory: The skill requires web research capabilities and generates structured LaTeX output.
  • Sanitization: No validation, escaping, or filtering steps are defined for the data ingested from the web before it is integrated into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:54 PM
Security Audit — agent-trust-hub — market-research