trade-fundamental
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources via web search tools, which could potentially contain malicious instructions aimed at the agent.
- Ingestion points: External data is retrieved from the web via
web_searchfor several categories including valuation, growth, profitability, and balance sheet metrics. - Boundary markers: Absent. The instructions do not define clear delimiters or provide the agent with specific warnings to ignore instructions found within search results.
- Capability inventory: The agent is instructed to process this external data and write it into a markdown file (
TRADE-FUNDAMENTAL-<TICKER>.md). - Sanitization: Absent. There is no defined process for sanitizing or validating the content retrieved from the web search before it is interpolated into the final report.
Audit Metadata