a-fund-monitor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands via monitor.sh to parse fund data and perform conditional logic. These operations are local to the skill's purpose and do not involve unsanitized user input.
  • [EXTERNAL_DOWNLOADS]: The skill fetches fund valuation and net value data from official EastMoney/1234567.com.cn domains (fundgz.1234567.com.cn and api.fund.eastmoney.com). These are well-known financial data services in the target region and the data fetched is structured text (JavaScript/JSON) used for display.
  • [REMOTE_CODE_EXECUTION]: While the skill uses curl to fetch data, it does not pipe this data to a shell or interpreter. It uses grep and cut to extract specific strings from the response, which is a safe way to handle external data.
  • [DATA_EXFILTRATION]: The skill sends the generated report to a local script ~/clawd/scripts/newsbot_send.py. This is part of the intended notification feature for the user and does not access sensitive system files or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:39 PM
Security Audit — agent-trust-hub — a-fund-monitor