earnings-watch
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, untrusted sources including news feeds and SEC filing text. Ingestion points: External content retrieved via
news_browseandsec_filing_read(SKILL.md). Boundary markers: None identified to separate external data from agent instructions. Capability inventory: Useshermes cron createfor persistence and command execution, alongside network data retrieval tools. Sanitization: No validation or filtering of external text content is mentioned before processing. - [EXTERNAL_DOWNLOADS]: The skill references the author's own repository
github.com/LLMQuant/skillsas a resource for analysis methods. - [COMMAND_EXECUTION]: The skill utilizes the
hermes cron createcommand to schedule and persist automated monitoring tasks.
Audit Metadata