daily-quotation-special-indicators

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs network requests to an external financial data provider to fetch stock indicators.
  • Evidence: The script scripts/API_01CON_02STKDATA_03STKQUOT_03DAYQUOTSPELINDX.js uses the Node.js https module to send POST requests to gstskill.95363.com (Caida Securities official domain).
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection because it ingests data from a remote API and displays it to the agent/user.
  • Ingestion points: Data is received via the queryAPI function from the external host gstskill.95363.com.
  • Boundary markers: The skill does not use specific delimiters or instructions to ignore potential commands embedded in the API response.
  • Capability inventory: The skill is primarily a data retrieval tool; it displays the JSON response but does not have file-writing or code-execution capabilities based on the received data.
  • Sanitization: The script prints the raw JSON response to the console without filtering or escaping content.
  • [COMMAND_EXECUTION]: The skill instructions provide examples for executing JavaScript files via the Node.js runtime.
  • Evidence: SKILL.md contains command-line examples such as node scripts/API_01CON_02STKDATA_03STKQUOT_03DAYQUOTSPELINDX.js --pageNo 1 --pageSize 10.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:14 PM
Security Audit — agent-trust-hub — daily-quotation-special-indicators