jqdatasdk

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface to the JoinQuant API, fetching external financial data based on stock codes and date parameters provided by the user. This data is then ingested by the agent for analysis.
  • Ingestion points: User-supplied arguments for stock codes, dates, and data types in market_data.py, financial_data.py, stock_info.py, and factor_data.py.
  • Boundary markers: The scripts output data in structured JSON format, but do not include specific delimiters to prevent the agent from interpreting fetched data as instructions.
  • Capability inventory: The skill performs network requests to the JoinQuant API via the jqdatasdk library and reads environment variables for authentication in auth.py.
  • Sanitization: Input validation is handled via the argparse library, ensuring parameters like codes and dates match expected formats.
  • [SAFE]: Authentication is handled correctly by reading credentials from environment variables (JQDATA_TOKEN, JQDATA_USERNAME, JQDATA_PASSWORD) rather than using hardcoded secrets or unsafe storage methods.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:36 PM
Security Audit — agent-trust-hub — jqdatasdk