tdxquant

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The _tdx_init.py script executes the wmic system utility via subprocess.run to locate the executable path of the TdxW.exe process. This is used solely for the benign purpose of automatically discovering the terminal's installation directory to load the required tqcenter library.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests market data, financial indicators, and securities metadata (e.g., company names, financial field values) from external market data servers via the terminal's API. This content is returned to the agent context without explicit sanitization or boundary markers, which is a standard surface for indirect prompt injection common in financial data skills. Evidence found in market_data.py and financial_data.py.
  • [COMMAND_EXECUTION]: The formula.py script enables the execution of TongDaXin technical analysis formulas (DSL) such as MACD or KDJ through the local tqcenter library as part of its core technical analysis functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:36 PM
Security Audit — agent-trust-hub — tdxquant