index-quotation
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes environment variables for authentication, specifically requiring
CDZQ_CLIENT_KEY. This aligns with security best practices for credential management as it avoids hardcoding secrets in the codebase. - [SAFE]: The scripts use only built-in Node.js modules like
httpsandprocess, meaning there are no external, unverifiable package dependencies that could introduce supply chain risks. - [SAFE]: Network operations are restricted to the service provider's domain (
gstskill.95363.com), which is consistent with the skill's stated purpose of fetching financial data. - [SAFE]: No evidence of prompt injection, obfuscation, persistence mechanisms, or privilege escalation was found in the provided files.
Audit Metadata