china-deck-refresh

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references legitimate financial data providers including iFind (Hithink RoyalFlush) and AkShare (a well-known open-source financial data library).
  • [COMMAND_EXECUTION]: The skill uses specialized tools for fetching market data, such as get_quote and get_financials, which are typical for financial analysis agents.
  • [DATA_EXFILTRATION]: The workflow includes a distribution step involving saving files to shared drives or preparing them for email. This behavior is consistent with the primary purpose of generating and sharing investment reports.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided presentation decks (PPTX) and linked Excel data sources. While this represents an ingestion point for untrusted data, no malicious exploitation patterns were observed.
  • Ingestion points: Existing PPTX files and linked Excel spreadsheets.
  • Boundary markers: None explicitly defined in the prompt interpolation logic.
  • Capability inventory: File system read/write, network access for financial APIs, and document conversion/distribution.
  • Sanitization: None explicitly mentioned for processing embedded text in slides.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 01:06 PM
Security Audit — agent-trust-hub — china-deck-refresh