you-finance

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with official API endpoints and MCP servers (api.you.com) owned by the author's organization (youdotcom-oss), representing standard vendor functionality.
  • [SAFE]: Authentication instructions reference the use of an environment variable (YDC_API_KEY) for API headers rather than hardcoding sensitive credentials.
  • [SAFE]: The skill incorporates clear safety guidelines instructing the agent to treat external search results as evidence rather than instructions, which mitigates risks associated with indirect prompt injection.
  • [SAFE]: The workflow for creating or reusing local scripts is presented as a legitimate developer-centric task for a code agent and does not involve downloading or executing code from untrusted remote sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 11:07 PM
Security Audit — agent-trust-hub — you-finance