stock-market-pro

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines several commands to be executed by the agent using 'uv run --script scripts/yf'. These operations are limited to financial data retrieval, ASCII reporting, and image generation for stock charts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data through ticker symbols and time periods. 1. Ingestion points: [TICKER] and [PERIOD] arguments in SKILL.md. 2. Boundary markers: Absent from command examples. 3. Capability inventory: The skill utilizes subprocess execution of a Python script. 4. Sanitization: Validation logic is expected to be contained within the scripts/yf file, which is an internal skill resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:06 AM
Security Audit — agent-trust-hub — stock-market-pro