ata-trading-atlas

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of its own components via npx from the author's GitHub repository (github.com/Zongming-He) and references optional MCP servers from the NPM registry. These sources are considered vendor-owned or well-known community resources.
  • [DATA_EXFILTRATION]: As part of its primary function, the skill transmits structured trading decisions, including ticker symbols, price levels, and analysis factors, to the vendor's API at api.agenttradingatlas.com.
  • [PROMPT_INJECTION]: The skill processes 'wisdom' data and workflow 'guidance' from the Agent Trading Atlas API, which creates an indirect prompt injection surface. Ingestion occurs at endpoints like /wisdom/query and /workflow/templates (SKILL.md, core-query-wisdom.md). Boundary markers and explicit sanitization for this ingested data are not described. The agent's capabilities include making trading decisions and performing further network operations based on this information.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 08:11 PM