quant-analyst
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [Prompt Injection] (SAFE): No markers of instruction override, jailbreaking, or system prompt extraction were found. The 'You are a quantitative analyst' instruction is a standard persona assignment.- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths (e.g., .ssh, .aws), or unauthorized network operations were detected. The skill focuses on local data processing.- [Obfuscation] (SAFE): The content is clear and readable. No Base64 encoding, zero-width characters, or homoglyph attacks were identified.- [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill references standard and trusted Python libraries: pandas, numpy, and scipy. No remote scripts or unverified packages are downloaded or executed.- [Privilege Escalation] (SAFE): No commands related to privilege escalation (e.g., sudo, chmod) were found.- [Persistence Mechanisms] (SAFE): No attempts to modify shell profiles or system startup tasks were identified.- [Indirect Prompt Injection] (SAFE): Although the skill processes external market data, it explicitly mandates 'Data quality first
- clean and validate all inputs' as its primary approach, which is a key mitigation strategy for data-borne injections.- [Dynamic Execution] (SAFE): No use of eval(), exec(), or runtime compilation techniques were found.
Audit Metadata