trade-sector

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of natural language instructions, sector mappings, and search query templates. It does not include any executable scripts, binary files, or commands that perform network operations or access sensitive system resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it is designed to ingest and process data from external search results.
  • Ingestion points: Data enters the agent's context via the search queries defined in the 'Data Collection' section of SKILL.md, covering performance rankings, money flows, and economic outlooks.
  • Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the retrieved search data.
  • Capability inventory: The skill is restricted to generating text-based markdown reports and does not have the capability to execute code, perform network exfiltration, or access the file system beyond creating the specified report file.
  • Sanitization: There is no evidence of sanitization or filtering logic for the external content retrieved during the data collection phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:46 AM
Security Audit — agent-trust-hub — trade-sector