usfiscaldata
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches financial data from the U.S. Department of the Treasury's official REST API (api.fiscaldata.treasury.gov), which is a well-known and trusted government service.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, which creates a surface for potentially embedded instructions in the fetched datasets.
- Ingestion points: The skill retrieves data using the
requestslibrary inSKILL.mdandreferences/examples.md. - Boundary markers: The data is ingested as structured JSON or CSV, but the instructions do not specify output delimiters for the agent's final response.
- Capability inventory: The skill frontmatter authorizes the use of
Read,Write,Edit, andBashtools. - Sanitization: Code examples in
references/response-format.mddemonstrate the use ofpd.to_numericandpd.to_datetimefor type conversion, which validates the structure and format of the ingested data. - [SAFE]: The skill implements a standard and well-documented interface for accessing public U.S. government financial data, following best practices for API interaction and data processing.
Audit Metadata