hhxg-market

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches financial market data and news from https://hhxg.top, which is the official domain of the skill author (恢恢量化). These operations are the primary intended function of the skill for data retrieval.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute its own internal Python scripts. These scripts use standard library modules (like urllib.request and json) to process data and do not execute arbitrary or externally provided shell commands.
  • [DATA_EXFILTRATION]: No access to sensitive local files (such as SSH keys, AWS credentials, or environment files) was detected. Network activity is confined to the vendor's data endpoints for fetching JSON payloads.
  • [PROMPT_INJECTION]: The skill's instructions in SKILL.md define an answer paradigm and guide the agent to provide financial information. There are no attempts to override agent safety constraints or ignore previous instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 05:56 AM