yahoo-data-fetcher
Warn
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The file
alltemp.shcontains shell commands that interact with system hardware and files, specifically reading/sys/class/thermal/thermal_zone0/tempand executingvcgencmd. These operations are unrelated to the skill's primary description as a finance tool. - [PROMPT_INJECTION]: There is a major mismatch between the documentation in
SKILL.md(Yahoo Data Fetcher) and the internal configuration in_meta.json(slug:cputemp). This form of metadata poisoning is deceptive, as the user or agent might expect a financial data service while the skill actually implements system monitoring utilities.
Audit Metadata