securities-trading

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill requires an environment variable CDZQ_CLIENT_KEY for API authentication. This follows security best practices by avoiding hardcoded secrets within the code or documentation. The SKILL.md file explicitly warns against hardcoding or leaking this sensitive information.
  • [EXTERNAL_DOWNLOADS]: The script scripts/API_01CON_05MKT_02SCRMKTTRD.js performs HTTPS POST requests to gstskill.95363.com to retrieve market data. This domain belongs to Caida Securities, the financial service provider described in the skill's purpose.
  • [COMMAND_EXECUTION]: The skill involves executing a local Node.js script to interact with the financial API. The script uses native Node.js modules, implements basic input validation for numeric arguments (parseInt), and does not perform any arbitrary shell command execution or unauthorized system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:14 PM
Security Audit — agent-trust-hub — securities-trading