yahoo-data-fetcher

Warn

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The file alltemp.sh contains shell commands that interact with system hardware and files, specifically reading /sys/class/thermal/thermal_zone0/temp and executing vcgencmd. These operations are unrelated to the skill's primary description as a finance tool.
  • [PROMPT_INJECTION]: There is a major mismatch between the documentation in SKILL.md (Yahoo Data Fetcher) and the internal configuration in _meta.json (slug: cputemp). This form of metadata poisoning is deceptive, as the user or agent might expect a financial data service while the skill actually implements system monitoring utilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 08:18 AM