investor-panel
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill is designed to perform role-played financial analysis using local data and documentation. The audit found no evidence of hidden malicious intent or security policy violations.\n- [EXTERNAL_DOWNLOADS]: Numerous links to well-known financial platforms (CNBC, Bloomberg, Reuters) are included for context and character mimicry. These are informational references and do not facilitate the download of untrusted or executable content.\n- [PROMPT_INJECTION]: The skill ingests data from local JSON cache files, creating a potential surface for indirect prompt injection. However, the agent's capabilities are restricted to local file operations, mitigating any significant risk. 1. Ingestion points: .cache/ticker files. 2. Boundary markers: None. 3. Capability inventory: Local file access only. 4. Sanitization: None.\n- [COMMAND_EXECUTION]: The skill utilizes local Python modules for metadata management and filtering. These operations are limited to the skill's defined script logic and do not involve running arbitrary or unsanitized shell commands.
Audit Metadata