insider-activity
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes data from external, untrusted sources such as SEC EDGAR filings, WebSearch results, and financial data websites.
- Ingestion points: The skill fetches content from SEC filings (Form 4, DEF 14A), third-party financial sites like Stock Analysis, and various search engine results as outlined in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters to isolate external content from the agent's core instructions.
- Capability inventory: The skill relies on network-based tools including WebFetch and WebSearch to gather data for analysis.
- Sanitization: The skill body lacks explicit instructions for validating, escaping, or filtering the content retrieved from external sources before it is processed by the agent.
Audit Metadata