china-clean-data-xls

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process external financial documents such as filings and audit reports. This introduces an indirect prompt injection surface where a malicious document could theoretically contain instructions to influence the agent. However, the skill instructions are purely procedural for data normalization and do not provide the agent with high-risk capabilities like shell execution or network exfiltration.
  • [CREDENTIALS_UNSAFE]: The documentation references the need for a WIND_API_KEY to access the Wind MCP service. It provides a legitimate link to the official vendor's portal and describes the required key format. There are no hardcoded credentials or unsafe handling of secrets detected.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known financial data services including Wind (万得), iFind (同花顺), and AkShare. These are established industry sources for financial data in the Chinese market.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 01:06 PM
Security Audit — agent-trust-hub — china-clean-data-xls