Caveat verdict

股票分析专家

stock-expert-cn

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

Fetches stock data from Tushare and Finnhub using user-provided API tokens in env vars for technical and fundamental analysis; matches the stated stock analysis purpose.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

68
security
100
transparency
90
maintenance

Findings (2)

Pattern match critical

Possible hardcoded credential

SKILL.md · code · TOKEN="abfa8a1c06b30afd16dbe62e0c656dc769f4c56280d7c686556761b2

Pattern match low

Python os.environ.get — reads environment variable

analyzer.py · prose · downgraded · os.environ.get(

Permissions & capabilities

Requires 2 environment variables. (2 sensitive: TUSHARE_TOKEN, FINNHUB_TOKEN). Requires 2 system binaries.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API