position-sizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns were detected. The skill performs all calculations locally and does not require external dependencies or network access.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided trade parameters which are interpolated into local shell commands. The risk is minimized by strict numeric type enforcement and validation.
  • Ingestion points: User-supplied trade parameters in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: File writing and script execution in scripts/position_sizer.py.
  • Sanitization: Argparse type checking and validation logic in scripts/position_sizer.py.
  • [COMMAND_EXECUTION]: The test suite (scripts/tests/test_position_sizer.py) uses subprocess.run to execute the main script for functional testing, which is a standard and safe practice for CLI tool development.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:20 AM
Security Audit — agent-trust-hub — position-sizer