analyse-smartmoney-13f

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a helper script watch.py and a Bun/TypeScript script top5-13f-report.ts for data management and reporting. These scripts perform routine file operations and local state management within the .cache and research directories.
  • [EXTERNAL_DOWNLOADS]: The skill fetches live financial data from the official SEC EDGAR endpoints (data.sec.gov and www.sec.gov/Archives). These are well-known, authoritative government services and the fetches are documented as the primary data source for the skill's legitimate purpose.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety guardrails was found. The instructions maintain a clear educational and analytical focus.
  • [DATA_EXFILTRATION]: No sensitive file access or exfiltration to unauthorized domains was detected. Network activity is strictly limited to SEC infrastructure and the user-specified roster of financial data sources.
  • [OBFUSCATION]: The skill's scripts and instructions are written in clear text with no evidence of hidden URLs, Base64 encoding of commands, or homoglyph-based evasion.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external XML data from the SEC, this data is parsed as structured financial records (CUSIPs, share counts, values) and is not interpolated as natural language instructions, effectively mitigating the risk of injection through tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — analyse-smartmoney-13f