earnings-calendar
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill connects to Financial Modeling Prep (
financialmodelingprep.com) to retrieve earnings data and company profiles. This is a well-known financial service required for the skill's primary function. - [COMMAND_EXECUTION]: The skill runs local Python scripts (
scripts/fetch_earnings_fmp.pyandscripts/generate_report.py) to process data and generate markdown reports. These scripts use standard libraries such asrequestsfor HTTP communication andjsonfor data handling. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external API, creating a theoretical attack surface for indirect prompt injection.
- Ingestion points: Data is ingested through
requests.getinscripts/fetch_earnings_fmp.pyand then read as JSON inscripts/generate_report.py. - Boundary markers: Absent; the skill does not wrap the external data in specific security delimiters in its output report.
- Capability inventory: Network access via
requestsand Python execution inscripts/fetch_earnings_fmp.py; file writing inSKILL.md(instructions) andscripts/generate_report.py. - Sanitization:
scripts/generate_report.pytruncates company name and sector strings to fix table widths, providing a basic level of data filtering.
Audit Metadata