financial-health

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches company identifiers and XBRL financial data from the official SEC EDGAR database (sec.gov). It also retrieves supplementary financial ratios and balance sheet information from well-known platforms like stockanalysis.com and gurufocus.com. These activities are consistent with the skill's stated purpose of financial analysis.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from financial websites and web search results, which constitutes an indirect prompt injection surface.
  • Ingestion points: External financial data from SEC, StockAnalysis, and GuruFocus, as well as qualitative information from WebSearch (SKILL.md).
  • Boundary markers: The skill instructions do not specify the use of delimiters or warnings to isolate untrusted data from the agent's logic.
  • Capability inventory: No dangerous capabilities, such as code execution or system file access, were found in the provided skill definition.
  • Sanitization: The skill does not explicitly detail any sanitization or validation processes for the data retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 07:24 PM