Fund Analyzer Pro
PassAudited by VirusTotal on Apr 28, 2026.
Findings (1)
The bundle is a comprehensive fund analysis tool that integrates with financial APIs (Tiantian Fund and Qieman). While it contains security vulnerabilities—specifically a hardcoded API key for the Qieman service in 'qieman-mcp-query.py' and the local storage of an encryption key in 'encrypt-holdings.py'—these appear to be unintentional design flaws rather than malicious intent. The code logic is consistent with the stated purpose of financial analysis, and there is no evidence of data exfiltration, unauthorized remote execution, or malicious prompt injection.
