tushare
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
tusharePython package via the Tsinghua University PyPI mirror. This is a standard and trusted source for package distribution. - [SAFE]: Analysis of the 200 files comprising this skill revealed no security risks.
- Secret Management: The skill correctly instructs users to provide their API token via an environment variable (
TUSHARE_TOKEN), which is a secure method for handling credentials. - Legitimate Functionality: The Python code snippets provided for each interface are standard calls to the
tusharelibrary and do not perform any unauthorized system or network operations. - No Obfuscation: All documentation and code snippets are in clear text, with no signs of hidden payloads or malicious encoding.
- Surface Analysis: While the skill retrieves external data such as news and corporate announcements, it does not possess any powerful capabilities (like shell execution or local file writing) that would make it vulnerable to indirect prompt injection impacts.
Audit Metadata