financial-data

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a rigorous process for verifying financial data using well-known and reputable financial websites such as SEC EDGAR, Macrotrends, and AAStocks. The use of these platforms is consistent with the skill's stated purpose of financial research.
  • [COMMAND_EXECUTION]: The instructions direct the agent to run the date command and project-specific Python scripts (e.g., tools/financial_rigor.py) for data verification and timestamping. These commands are relevant to the analytical workflow and operate within the local project context.
  • [DATA_EXFILTRATION]: Outbound network access is directed toward a predefined list of public financial domains for data retrieval. There are no patterns indicating the exfiltration of sensitive local data or credentials.
  • [PROMPT_INJECTION]: The skill processes data from external websites, which represents an indirect prompt injection surface. This is mitigated by explicit requirements for cross-validation between independent sources (Step 2) and mandatory reporting of data discrepancies, which helps detect anomalous or malicious content injected into financial metrics.
  • Ingestion points: External financial domains (Macrotrends, StockAnalysis, AAStocks, Eastmoney, SEC, HKEX).
  • Boundary markers: The instructions mandate a specific verification protocol and error calculation between two independent sources.
  • Capability inventory: Shell command execution (date, python3), network access for data retrieval, and local file reading for repository tools.
  • Sanitization: Discrepancy labeling and error-rate calculations are required to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 07:18 AM
Security Audit — agent-trust-hub — financial-data