sec-filing-puller

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches company data and financial facts from official government domains (sec.gov and data.sec.gov). These downloads are essential for the skill's stated purpose and target well-known, trusted service endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external SEC filings, creating a vulnerability surface for indirect injection.
  • Ingestion points: Data enters the system through JSON responses from SEC API endpoints in scripts/sec_pull.py.
  • Boundary markers: The instructions specify markdown table formatting but do not implement explicit delimiters or 'ignore' instructions for the retrieved data content.
  • Capability inventory: The skill has the capability to perform network requests and write cache files to the user's home directory (~/.cache/sec-filing-puller).
  • Sanitization: Retrieved facts are processed as structured JSON; however, descriptive labels from the filings are displayed without specific sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — sec-filing-puller