skills/hkuds/vibe-trading/eastmoney/Gen Agent Trust Hub

eastmoney

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates as a data source for financial market information, connecting to well-known and legitimate services like Eastmoney, the SEC, and Yahoo Finance. No evidence of malicious code execution, persistence, or data exfiltration was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external financial APIs, which is an inherent surface for indirect prompt injection. However, the data retrieved is structured financial information and the skill lacks dangerous capabilities that would make such an injection exploitable.
  • Ingestion points: Multiple API endpoints from eastmoney.com, sec.gov, yahoo.com, and 10jqka.com.cn listed in the reference files.
  • Boundary markers: Data is encapsulated within a structured JSON response envelope ({"ok": true, "data": ...}).
  • Capability inventory: Capabilities are restricted to HTTP fetching and JSON data extraction; no subprocess execution or dynamic code evaluation (eval/exec) is present.
  • Sanitization: The skill identifies and strips JSONP callbacks from API responses to ensure only data is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:26 PM
Security Audit — agent-trust-hub — eastmoney