value-dividend-screener
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill uses environment variables (
FMP_API_KEY,FINVIZ_API_KEY) for API authentication, which is a recommended practice for secret management. No hardcoded credentials or private keys were found in the skill files. - [EXTERNAL_DOWNLOADS]: The skill interfaces with Financial Modeling Prep (FMP) and FINVIZ Elite, which are well-known financial data providers. All network requests are performed via the standard
requestslibrary targeting official domains. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from financial APIs. While this represents an attack surface, the data is parsed as structured JSON and CSV formats and is strictly validated through quantitative filtering (converting values to floats/integers) before being summarized by the agent, effectively mitigating the risk of prompt injection from remote data.
- [COMMAND_EXECUTION]: The skill script uses standard file system operations to save screening results to a JSON file. It does not execute arbitrary shell commands, spawn subprocesses with untrusted input, or invoke dynamic code execution functions.
Audit Metadata