fintel-data
Warn
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdfile contains a shell script using the!commandsyntax that executes automatically when the skill is loaded. This script probes the environment and the filesystem (searching.envfiles in local and parent directories viagit rev-parse) to determine if aFINTEL_API_KEYis present. - [COMMAND_EXECUTION]: The skill provides explicit shell pipelines using
grep,head,cut, andsedfor the agent to parse local configuration files and extract sensitive credentials. - [CREDENTIALS_UNSAFE]: The skill is designed to automatically locate and read API keys stored in
.envfiles. While these keys are used for the intended financial data service, the automated discovery and extraction of secrets from the filesystem is a high-risk pattern. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user input such as company names and tickers and instructs the agent to interpolate them directly into
curlcommands. 1. Ingestion points: User input for search queries and ticker symbols inSKILL.md(Step 2 and Step 3). 2. Boundary markers: None present in the suggested shell commands. 3. Capability inventory: Network requests viacurltoapi.fintel.io. 4. Sanitization: None specified in the instructions for handling the user-provided strings.
Audit Metadata