canslim-screener

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, including company profiles and news headlines retrieved from the Financial Modeling Prep (FMP) and Finviz APIs. This data is used to generate human-readable reports that the agent is then tasked to analyze and interpret.
  • Ingestion points: Untrusted data enters the agent context through the fmp_client.py and finviz_stock_client.py scripts which fetch market data, and the news scanning logic referenced in fmp_api_endpoints.md and new_highs_calculator.py.
  • Boundary markers: The Markdown reports produced by report_generator.py do not utilize delimiters or specific instructions to the agent to disregard potentially malicious instructions embedded within the processed stock data.
  • Capability inventory: The skill utilizes the requests library for network communication and performs file write operations to save results.
  • Sanitization: The skill lacks logic to sanitize or escape external strings (like news titles or company descriptions) before they are interpolated into the Markdown reports, leaving the agent vulnerable to instructions hidden in external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — canslim-screener