alphagbm-macro-view

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill communicates with official vendor infrastructure at alphagbm.zeabur.app and refers to alphagbm.com. These domains are consistent with the skill author 'AlphaGBM'.
  • [SAFE]: Sensitive credentials are handled securely using environment variables (ALPHAGBM_API_KEY) rather than being hardcoded in the skill definition.
  • [DATA_EXPOSURE]: The skill transmits indicator selection (e.g., 'VIX') to the vendor's API, which is necessary for the stated functionality of tracking macro variables.
  • [PROMPT_INJECTION]: The skill ingests 'impact_analysis' text from an external API. This represents a surface for indirect prompt injection where malicious instructions could theoretically be delivered from the backend. However, because the skill lacks dangerous capabilities like local file writes or arbitrary command execution, the risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 11:42 AM
Security Audit — agent-trust-hub — alphagbm-macro-view