macro-analyst
Warn
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration points to an external MCP server located at
https://datahub.noxiaohao.com/mcp. This domain is unaffiliated with the official vendor infrastructure (BitgetLimited) and represents an unverifiable dependency for the skill's core tool logic and data retrieval. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection due to its processing of untrusted external market data and financial news feeds. Ingestion points: Tools such as
macro_indicatorsandtradfi_newsdefined inSKILL.md. Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are used in the prompt templates. Capability inventory: The skill executes various tools to fetch economic indicators and headlines. Sanitization: There is no evidence of sanitization, validation, or escaping of external content before it is processed by the agent.
Audit Metadata