crible-cli
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads financial datasets, corporate filings, and market data from several external platforms, including Hugging Face, the SEC EDGAR database, and the European Central Bank (ECB). These downloads are necessary for the tool's core functionality of financial analysis and screening.
- [REMOTE_CODE_EXECUTION]: Instructions guide the installation and execution of the crible CLI tool directly from the vendor's repository on GitHub (maxgfr/crible) via the uv tool manager. This involves executing code provided by the repository at runtime.
- [COMMAND_EXECUTION]: The skill performs various terminal-based operations, such as screening stock universes, crawling financial databases, and exporting results to local CSV files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied screening queries through a command-line interface. 1. Ingestion points: User-provided filter strings passed to the crible screen command. 2. Boundary markers: The tool enforces a whitelist of filterable fields retrieved via the crible fields command. 3. Capability inventory: Includes file system write operations (export), network access for data enrichment (ingest), and terminal command execution. 4. Sanitization: Input is validated against a structured Domain Specific Language (DSL) that defines allowed operators and field names.
Audit Metadata