congress-stock-tracker

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code, instructions, and resources are consistent with its stated purpose of scraping public congressional trade disclosures and performing policy/market correlation analysis; it does not request credentials or install arbitrary third‑party code.

This skill appears to be internally consistent: it scrapes publicly available congressional trade disclosure pages and analyzes them against the included committee/analysis references. Before installing, consider: (1) scraping etiquette and terms of service — verify that fetching Capitol Trades / Quiver is permitted and respect rate limits; (2) data limitations — many disclosures report ranges and have up to 45‑day delays, so treat outputs as indicative, not definitive investment advice; (3) web searches invoked at runtime may contact arbitrary external sites — if you need to restrict outbound network access, run the skill in a sandboxed environment first; (4) review the full fetch_trades.py (the provided file appears focused on parsing and analysis) for any unexpected network endpoints or logging of outputs to remote servers; and (5) if you will rely on this for decisions, validate results against primary sources (official disclosures) and consider legal/regulatory/privacy implications of using aggregated political trading data.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.