you-finance

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill manages authentication securely by instructing the agent to use the YDC_API_KEY environment variable for API requests, avoiding hardcoded secrets or unsafe credential storage.
  • [EXTERNAL_DOWNLOADS]: The skill references official You.com MCP servers and documentation URLs for market data. These connections are consistent with the skill's primary purpose and the developer's identity.
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly addresses the risk of processing external data from financial sources. It includes safety guidelines that mandate treating search results as untrusted evidence rather than instructions, and requires citing sources to maintain data integrity.
  • [DYNAMIC_EXECUTION]: To facilitate finance research, the skill may generate or update small local scripts to interact with the Finance Research API. This behavior is scoped to the agent's development workflow and follows standard practices for API integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 02:58 PM
Security Audit — agent-trust-hub — you-finance