wind-mcp-skill

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill implements an automated background update mechanism in scripts/update-check.mjs. It fetches updates from the vendor's official repositories (GitHub and Gitee) using the npx skills utility. These downloads target official vendor infrastructure and are consistent with professional maintenance practices.
  • [COMMAND_EXECUTION]: The CLI (scripts/cli.mjs) and update script (scripts/update-check.mjs) execute system commands including node, git, and npx. These are used for operational tasks like checking for updates via git ls-remote and performing installations.
  • [DYNAMIC_EXECUTION]: To ensure the update process can complete even if the skill's own files are modified, the script copies itself to a temporary cache directory (~/.cache/wind-aifinmarket/) and executes from that location as a detached process.
  • [INDIRECT_PROMPT_INJECTION]: Several tools, such as economic_search_indicator and get_financial_data, accept natural language queries as input. These inputs are passed to the vendor's MCP server for processing. While this represents a standard tool interface, it is an ingestion point for potentially untrusted data that the agent handles.
  • [SAFE]: The skill follows security best practices for secret management. API keys stored via the setup-key command are written to configuration files with restricted file permissions (0o600), ensuring they are only accessible by the owner.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 12:26 PM
Security Audit — agent-trust-hub — wind-mcp-skill