risk-assessment

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources which presents a surface for potential indirect prompt injection.
  • Ingestion points: The skill retrieves text from SEC 10-K filings and news summaries via WebSearch as described in the 'Data Fetching Process' of SKILL.md.
  • Boundary markers: The instructions in SKILL.md do not define specific delimiters or instructions for the agent to disregard potential prompts embedded within the retrieved content.
  • Capability inventory: The skill utilizes WebSearch and API resolution for data gathering in SKILL.md. It does not demonstrate capabilities for file modification, persistent storage, or arbitrary code execution.
  • Sanitization: The skill does not describe any logic for sanitizing or validating the retrieved text content before processing.
  • [EXTERNAL_DOWNLOADS]: The skill fetches public financial ratios and data from the SEC and Stock Analysis service as part of its core functionality for company assessment. These are documented as standard data sources for the skill's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:28 AM
Security Audit — agent-trust-hub — risk-assessment