you-finance
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts with official API endpoints and MCP servers (
api.you.com) owned by the author's organization (youdotcom-oss), representing standard vendor functionality. - [SAFE]: Authentication instructions reference the use of an environment variable (
YDC_API_KEY) for API headers rather than hardcoding sensitive credentials. - [SAFE]: The skill incorporates clear safety guidelines instructing the agent to treat external search results as evidence rather than instructions, which mitigates risks associated with indirect prompt injection.
- [SAFE]: The workflow for creating or reusing local scripts is presented as a legitimate developer-centric task for a code agent and does not involve downloading or executing code from untrusted remote sources.
Audit Metadata