financial-indicator-data
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill connects to Caida Securities' official API endpoint at gstskill.95363.com. This is a primary, legitimate function of the tool and uses a well-known financial service domain.- [PROMPT_INJECTION]: The skill processes user-supplied stock codes and dates via command-line arguments.
- Ingestion points: The SECUCODE and ENDDATE arguments in scripts/API_01CON_02STKDATA_04FINRPFM_07FININDXDATA.js are used to build the API query.
- Boundary markers: Data is serialized using JSON.stringify, which prevents parameter injection into the request structure.
- Capability inventory: The skill is limited to making network requests to the specified API and does not perform any system-level command execution.
- Sanitization: Pagination parameters (pageNo, pageSize) are strictly converted to integers using parseInt.
Audit Metadata