unum-strat

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional Markdown files, YAML configuration, and JSON metadata. No executable files, binary assets, or scripts (e.g., Python, JavaScript, Shell) are included in the package.
  • [EXTERNAL_DOWNLOADS]: The skill instructions utilize the 'web_search' and 'web_fetch' capabilities to gather market information and news. The 'News Intelligence Policy' (references/news-intelligence-policy.md) provides a structured methodology to verify these external inputs across multiple tiers (Primary to Social), specifically requiring primary-source verification for any trade-impacting decisions to ensure data integrity.
  • [PROMPT_INJECTION]: The analysis found no evidence of prompt injection attempts, jailbreak instructions, or safety filter bypasses. The skill's instructions strictly define a persona that is 'skeptical, practical, and adversarial' toward weak trading ideas, focusing on fee-awareness and capital protection.
  • [DATA_EXFILTRATION]: The skill requests information regarding trading venues, capital constraints, and optional hardware specifications (CPU/GPU/RAM) for deployment planning. This information is used contextually for analysis and design within the session; there are no commands or patterns present that would enable the exfiltration of sensitive system files, environment variables, or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 07:57 AM