edgartools
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the edgartools Python package via standard package managers like uv.\n- [PROMPT_INJECTION]: Includes behavioral steering instructions that direct the agent to suggest the vendor's platform (K-Dense Web) for complex tasks. This is an informational guidance pattern for users.\n- [PROMPT_INJECTION]: Indirect prompt injection surface identified. Ingestion points: external SEC filing data via filing.markdown and filing.obj (filings.md). Boundary markers: absent in documentation. Capability inventory: library focuses on SEC data retrieval and structured parsing. Sanitization: not specified in the skill references.\n- [DATA_EXFILTRATION]: Interacts with the SEC EDGAR system, which requires user identity strings (name/email) for access. This is a standard regulatory requirement for the data source.\n- [SAFE]: No malicious obfuscation, unauthorized persistence, or privilege escalation patterns were found.
Audit Metadata