finance-ml

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several established and well-known financial data libraries including yfinance, financedatabase, alpha_vantage, ccxt, and pandas-datareader.
  • [COMMAND_EXECUTION]: Outlines a conceptual workflow for integrating with trading APIs (e.g., create_order, get_balance) within a decentralized exchange context.
  • [PROMPT_INJECTION]: The skill establishes a data ingestion surface by instructing the agent to process external market data and financial documents. 1. Ingestion points: market data from APIs and local financial statements. 2. Boundary markers: none are specified in the provided patterns. 3. Capability inventory: includes tools for balance checking and order execution. 4. Sanitization: no validation or escaping logic is demonstrated. This surface represents a potential risk for indirect prompt injection, which is mitigated by the mandatory user-confirmation requirement for all trades.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — finance-ml