china-clean-data-xls
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process external financial documents such as filings and audit reports. This introduces an indirect prompt injection surface where a malicious document could theoretically contain instructions to influence the agent. However, the skill instructions are purely procedural for data normalization and do not provide the agent with high-risk capabilities like shell execution or network exfiltration.
- [CREDENTIALS_UNSAFE]: The documentation references the need for a
WIND_API_KEYto access the Wind MCP service. It provides a legitimate link to the official vendor's portal and describes the required key format. There are no hardcoded credentials or unsafe handling of secrets detected. - [EXTERNAL_DOWNLOADS]: The skill references several well-known financial data services including Wind (万得), iFind (同花顺), and AkShare. These are established industry sources for financial data in the Chinese market.
Audit Metadata