earnings-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from untrusted external sources. * Ingestion points: Web search results and external financial websites (references/workflow.md). * Boundary markers: Not explicitly required in instructions. * Capability inventory: Web search, DOCX creation, and Python code execution. * Sanitization: No specific sanitization mentioned.
  • [COMMAND_EXECUTION]: The skill dynamically generates Python code using matplotlib, pandas, and seaborn to create financial charts (SKILL.md). * Pattern: Local execution of plotting logic based on processed quarterly data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:21 PM
Security Audit — agent-trust-hub — earnings-analysis