trade-fundamental

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources via web search tools, which could potentially contain malicious instructions aimed at the agent.
  • Ingestion points: External data is retrieved from the web via web_search for several categories including valuation, growth, profitability, and balance sheet metrics.
  • Boundary markers: Absent. The instructions do not define clear delimiters or provide the agent with specific warnings to ignore instructions found within search results.
  • Capability inventory: The agent is instructed to process this external data and write it into a markdown file (TRADE-FUNDAMENTAL-<TICKER>.md).
  • Sanitization: Absent. There is no defined process for sanitizing or validating the content retrieved from the web search before it is interpolated into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:46 AM
Security Audit — agent-trust-hub — trade-fundamental