Finance News Assistant

PassAudited by VirusTotal on Apr 16, 2026.

Findings (1)

The skill bundle hardcodes a specific, non-standard domain (tczlld.com) for all financial data retrieval and 'AI decision' API calls, requiring the user to provide a STOCK_API_TOKEN. This architecture directs potentially sensitive financial interests and authentication credentials to an unverified external endpoint. While the instructions in SKILL.md and the extensive reference documents (e.g., anti-hallucination.md) emphasize data accuracy and professional reporting, the centralized collection of tokens and queries via an obscure domain is a high-risk pattern that could facilitate credential harvesting.