canslim-screener
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, including company profiles and news headlines retrieved from the Financial Modeling Prep (FMP) and Finviz APIs. This data is used to generate human-readable reports that the agent is then tasked to analyze and interpret.
- Ingestion points: Untrusted data enters the agent context through the
fmp_client.pyandfinviz_stock_client.pyscripts which fetch market data, and the news scanning logic referenced infmp_api_endpoints.mdandnew_highs_calculator.py. - Boundary markers: The Markdown reports produced by
report_generator.pydo not utilize delimiters or specific instructions to the agent to disregard potentially malicious instructions embedded within the processed stock data. - Capability inventory: The skill utilizes the
requestslibrary for network communication and performs file write operations to save results. - Sanitization: The skill lacks logic to sanitize or escape external strings (like news titles or company descriptions) before they are interpolated into the Markdown reports, leaving the agent vulnerable to instructions hidden in external data.
Audit Metadata