sec-filing-puller
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches company data and financial facts from official government domains (
sec.govanddata.sec.gov). These downloads are essential for the skill's stated purpose and target well-known, trusted service endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external SEC filings, creating a vulnerability surface for indirect injection.
- Ingestion points: Data enters the system through JSON responses from SEC API endpoints in
scripts/sec_pull.py. - Boundary markers: The instructions specify markdown table formatting but do not implement explicit delimiters or 'ignore' instructions for the retrieved data content.
- Capability inventory: The skill has the capability to perform network requests and write cache files to the user's home directory (
~/.cache/sec-filing-puller). - Sanitization: Retrieved facts are processed as structured JSON; however, descriptive labels from the filings are displayed without specific sanitization.
Audit Metadata