trade-skills
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill identifies and downloads required sub-skills (akshare-data and tianqin-data) from the author's own repository (https://github.com/PPsteven/skills). This behavior is part of the core functionality for the router skill to ensure its dependencies are present.
- [REMOTE_CODE_EXECUTION]: The skill uses the
npx skills addcommand to fetch and install external code from the author's GitHub repository. This is an expected management operation for this skill and targets a known vendor resource. - [COMMAND_EXECUTION]: The skill utilizes shell scripts to check for the existence of skill directories and to automate the installation process. These commands are transparently documented in the skill instructions and are limited to environment verification and setup.
Audit Metadata