earnings-analysis
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from untrusted external sources. * Ingestion points: Web search results and external financial websites (references/workflow.md). * Boundary markers: Not explicitly required in instructions. * Capability inventory: Web search, DOCX creation, and Python code execution. * Sanitization: No specific sanitization mentioned.
- [COMMAND_EXECUTION]: The skill dynamically generates Python code using matplotlib, pandas, and seaborn to create financial charts (SKILL.md). * Pattern: Local execution of plotting logic based on processed quarterly data.
Audit Metadata