sec-filing-reader

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from official government domains, specifically sec.gov and efts.sec.gov, which are recognized as well-known and trusted services for financial information.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from filing documents. 1. Ingestion points: SEC filing text and HTML retrieved through WebFetch. 2. Boundary markers: The skill does not define specific delimiters to isolate external text from instructions. 3. Capability inventory: The skill is restricted to information retrieval and summarization, with no access to high-risk operations like shell command execution or local file writing. 4. Sanitization: No specific filtering or validation is described for the content of the retrieved filings.
  • [SAFE]: The skill's implementation follows the expected behavior for a financial report reader and lacks any patterns of obfuscation, privilege escalation, or unauthorized data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:26 AM
Security Audit — agent-trust-hub — sec-filing-reader