SEC Filings

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

The skill facilitates SEC filing searches by instructing the agent to use `curl` to access a third-party API (`labs.lovelace.ai`) in `SKILL.md`, which involves shell-based network access and potential shell injection vulnerabilities if parameters are not sanitized. While the functionality is aligned with the stated purpose, the use of an external intermediary and the presence of an anomalous future-dated timestamp (2026) in `_meta.json` are flagged as risky indicators under the provided guidelines.