usfiscaldata

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches financial data from the U.S. Department of the Treasury's official REST API (api.fiscaldata.treasury.gov), which is a well-known and trusted government service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, which creates a surface for potentially embedded instructions in the fetched datasets.
  • Ingestion points: The skill retrieves data using the requests library in SKILL.md and references/examples.md.
  • Boundary markers: The data is ingested as structured JSON or CSV, but the instructions do not specify output delimiters for the agent's final response.
  • Capability inventory: The skill frontmatter authorizes the use of Read, Write, Edit, and Bash tools.
  • Sanitization: Code examples in references/response-format.md demonstrate the use of pd.to_numeric and pd.to_datetime for type conversion, which validates the structure and format of the ingested data.
  • [SAFE]: The skill implements a standard and well-documented interface for accessing public U.S. government financial data, following best practices for API interaction and data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:51 AM
Security Audit — agent-trust-hub — usfiscaldata