ab-ah-premium-monitor
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts from a sibling directory to retrieve market data. Evidence: data-queries.md instructions to run ../findata-toolkit-cn/scripts/views_runner.py.
- [EXTERNAL_DOWNLOADS]: The skill automates the installation of required Python libraries from a local requirements file. Evidence: data-queries.md pip install command for ../findata-toolkit-cn/requirements.txt.
- [PROMPT_INJECTION]: A theoretical indirect prompt injection surface exists through the processing of third-party financial data. Ingestion points: JSON data from financial APIs via views_runner.py. Capability inventory: Execution of shell commands and local scripts. Sanitization: None explicitly stated in instructions.
Audit Metadata