earnings-calendar

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Financial Modeling Prep (FMP) API and manual user input. While these sources are expected for the skill's purpose, the instructions lack explicit sanitization or boundary markers when interpolating this external content into the generated markdown report. This creates an attack surface where malicious instructions embedded in company names or other data fields could influence the agent's interpretation. 1. Ingestion points: The skill ingests untrusted data via scripts/fetch_earnings_fmp.py (API responses) and through the Manual Data Entry fallback described in SKILL.md. 2. Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded commands within the processed data. 3. Capability inventory: The skill utilizes subprocess calls to execute local Python scripts and performs network GET requests to the FMP API. 4. Sanitization: scripts/generate_report.py performs basic truncation on company names but does not escape markdown control characters or validate the content against a strict schema before presentation.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to financialmodelingprep.com to fetch earnings calendar and company profile data. This is a functional requirement for the skill's stated purpose.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts scripts/fetch_earnings_fmp.py and scripts/generate_report.py to automate data retrieval and report formatting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — earnings-calendar