alphaear-stock

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to search and retrieve historical stock price data (OHLCV) and fundamentals for A-Share, HK, and US markets.
  • [EXTERNAL_DOWNLOADS]: Fetches financial data from well-known and reputable services including Yahoo Finance (via yfinance) and EastMoney (via akshare and direct HTTP calls). These operations are consistent with the skill's stated purpose and target public financial APIs.
  • [COMMAND_EXECUTION]: No dangerous system command execution or shell injection vulnerabilities were detected. The use of environment variables for proxy configuration follows standard network management practices.
  • [DATA_EXFILTRATION]: Data access is restricted to financial market tickers and prices. The skill implements a local SQLite database (data/signal_flux.db) for caching purposes, which does not involve sensitive user information or unauthorized data transmission.
  • [PROMPT_INJECTION]: The instructions and metadata in SKILL.md are descriptive and do not contain patterns attempting to override agent behavior or bypass safety filters.
  • [SAFE]: The skill's logic for handling network failures, such as temporarily unsetting proxies to attempt direct connections for specific markets, is a robust error-handling mechanism and does not present a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 05:57 PM