fintel-data

Warn

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file contains a shell script using the !command syntax that executes automatically when the skill is loaded. This script probes the environment and the filesystem (searching .env files in local and parent directories via git rev-parse) to determine if a FINTEL_API_KEY is present.
  • [COMMAND_EXECUTION]: The skill provides explicit shell pipelines using grep, head, cut, and sed for the agent to parse local configuration files and extract sensitive credentials.
  • [CREDENTIALS_UNSAFE]: The skill is designed to automatically locate and read API keys stored in .env files. While these keys are used for the intended financial data service, the automated discovery and extraction of secrets from the filesystem is a high-risk pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user input such as company names and tickers and instructs the agent to interpolate them directly into curl commands. 1. Ingestion points: User input for search queries and ticker symbols in SKILL.md (Step 2 and Step 3). 2. Boundary markers: None present in the suggested shell commands. 3. Capability inventory: Network requests via curl to api.fintel.io. 4. Sanitization: None specified in the instructions for handling the user-provided strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 26, 2026, 12:30 PM
Security Audit — agent-trust-hub — fintel-data