stk-stock-analysis

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the execution of multiple sub-commands via a local 'stk' CLI tool (e.g., 'stk market', 'stk stock scan', 'stk watchlist') to aggregate market data. This is the primary mechanism for its functionality.
  • [DATA_EXPOSURE]: The skill automates the creation and updating of local files within an Obsidian vault located at '14_Trading/DailyReport/'. This file system access is intended for the storage of generated financial reports.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from market news sources (CLS and THS) through the 'stk market news' command. Although this presents a surface for indirect prompt injection, the risk is mitigated by the structured workflow and specific markdown templates used to format the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 01:47 AM
Security Audit — agent-trust-hub — stk-stock-analysis