ata-trading-atlas
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of its own components via npx from the author's GitHub repository (github.com/Zongming-He) and references optional MCP servers from the NPM registry. These sources are considered vendor-owned or well-known community resources.
- [DATA_EXFILTRATION]: As part of its primary function, the skill transmits structured trading decisions, including ticker symbols, price levels, and analysis factors, to the vendor's API at api.agenttradingatlas.com.
- [PROMPT_INJECTION]: The skill processes 'wisdom' data and workflow 'guidance' from the Agent Trading Atlas API, which creates an indirect prompt injection surface. Ingestion occurs at endpoints like /wisdom/query and /workflow/templates (SKILL.md, core-query-wisdom.md). Boundary markers and explicit sanitization for this ingested data are not described. The agent's capabilities include making trading decisions and performing further network operations based on this information.
Audit Metadata