unum-strat
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional Markdown files, YAML configuration, and JSON metadata. No executable files, binary assets, or scripts (e.g., Python, JavaScript, Shell) are included in the package.
- [EXTERNAL_DOWNLOADS]: The skill instructions utilize the 'web_search' and 'web_fetch' capabilities to gather market information and news. The 'News Intelligence Policy' (references/news-intelligence-policy.md) provides a structured methodology to verify these external inputs across multiple tiers (Primary to Social), specifically requiring primary-source verification for any trade-impacting decisions to ensure data integrity.
- [PROMPT_INJECTION]: The analysis found no evidence of prompt injection attempts, jailbreak instructions, or safety filter bypasses. The skill's instructions strictly define a persona that is 'skeptical, practical, and adversarial' toward weak trading ideas, focusing on fee-awareness and capital protection.
- [DATA_EXFILTRATION]: The skill requests information regarding trading venues, capital constraints, and optional hardware specifications (CPU/GPU/RAM) for deployment planning. This information is used contextually for analysis and design within the session; there are no commands or patterns present that would enable the exfiltration of sensitive system files, environment variables, or hardcoded credentials.
Audit Metadata