fund-manager-alpha

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a specialized tool for financial due diligence that leverages public data sources and established open-source libraries.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted external data, as it fetches financial forum posts, news, and PDF reports for sentiment analysis and behavioral reconstruction.
  • Ingestion points: External content is retrieved from EastMoney Guba (forum), news platforms, and corporate PDF filings.
  • Boundary markers: There are no explicit instructions within the skill to delimit or ignore potentially malicious instructions embedded in the retrieved financial data.
  • Capability inventory: The skill utilizes standard Python financial libraries (akshare, pyfolio), browser automation for data retrieval, and local filesystem access for report generation and caching.
  • Sanitization: The skill focuses on extracting specific financial metrics and structured summaries, which naturally limits the impact of embedded instructions, and it lacks high-privilege capabilities (like shell execution of data) that would escalate the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:09 PM
Security Audit — agent-trust-hub — fund-manager-alpha