twelvedata

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes environment variables (TWELVEDATA_API_KEY) for authentication, avoiding hardcoded credentials.
  • [SAFE]: Network operations are confined to the official Twelve Data API (api.twelvedata.com) and are performed using the platform's recommended proxy-safe HTTP clients (core.http_client and sidecar.proxy_client).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a remote financial API. 1. Ingestion points: Data is fetched from api.twelvedata.com in tools/client.py and exports.py. 2. Boundary markers: Absent. 3. Capability inventory: The skill performs HTTP GET requests to fetch financial data. 4. Sanitization: The skill implements an error handler (_explain_error in exports.py) that filters raw API error bodies, preventing potentially untrusted content from being echoed back to the agent context.
  • [SAFE]: Analysis of the skill's scripts and metadata found no evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:01 AM
Security Audit — agent-trust-hub — twelvedata