investment-management

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess calls to orchestrate internal scripts and integrate with local tools like the Interceptor browser controller. These operations are limited to the skill's own directory or known local binaries and are used for legitimate functionality such as backtesting and evidence capture.
  • [EXTERNAL_DOWNLOADS]: Fetches market data (prices, fundamentals, macro indicators) from established financial service providers including Yahoo Finance, CoinGecko, and the Federal Reserve Economic Data (FRED) API. All data retrieval is consistent with the skill's stated purpose of investment research.
  • [CREDENTIALS_UNSAFE]: Security best practices are followed for credential management. API keys and webhook secrets are sourced from environment variables or local configuration files, and secret comparison is performed using constant-time algorithms to prevent timing attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 03:33 PM
Security Audit — agent-trust-hub — investment-management