a-fund-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands via
monitor.shto parse fund data and perform conditional logic. These operations are local to the skill's purpose and do not involve unsanitized user input. - [EXTERNAL_DOWNLOADS]: The skill fetches fund valuation and net value data from official EastMoney/1234567.com.cn domains (
fundgz.1234567.com.cnandapi.fund.eastmoney.com). These are well-known financial data services in the target region and the data fetched is structured text (JavaScript/JSON) used for display. - [REMOTE_CODE_EXECUTION]: While the skill uses
curlto fetch data, it does not pipe this data to a shell or interpreter. It usesgrepandcutto extract specific strings from the response, which is a safe way to handle external data. - [DATA_EXFILTRATION]: The skill sends the generated report to a local script
~/clawd/scripts/newsbot_send.py. This is part of the intended notification feature for the user and does not access sensitive system files or credentials.
Audit Metadata