position-sizer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns were detected. The skill performs all calculations locally and does not require external dependencies or network access.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided trade parameters which are interpolated into local shell commands. The risk is minimized by strict numeric type enforcement and validation.
- Ingestion points: User-supplied trade parameters in SKILL.md.
- Boundary markers: Absent.
- Capability inventory: File writing and script execution in scripts/position_sizer.py.
- Sanitization: Argparse type checking and validation logic in scripts/position_sizer.py.
- [COMMAND_EXECUTION]: The test suite (scripts/tests/test_position_sizer.py) uses subprocess.run to execute the main script for functional testing, which is a standard and safe practice for CLI tool development.
Audit Metadata