skills/hkuds/vibe-trading/qveris/Gen Agent Trust Hub

qveris

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation describes a mechanism for the agent to download full JSON payloads via signed URLs ("full_content_file_url") when API responses are too large for direct inclusion. This involves fetching external content from a dynamically provided remote source.
  • [PROMPT_INJECTION]: As a data-source skill that retrieves content from multiple third-party providers (e.g., FMP, AlphaVantage, various news feeds), it possesses an inherent indirect prompt injection surface. Maliciously crafted data from these sources could theoretically influence the agent's behavior, though no specific instructions for doing so are present in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 10:24 PM
Security Audit — agent-trust-hub — qveris