Book a 30-minute demo →
Skill scan report

alphaear-news

View on GitHub
18 Low Automated analysis flagged 3 potential risk patterns.

What this skill does

Fetch real-time hot news, generate unified trend reports, and retrieve Polymarket prediction data from multiple sources (Weibo, Zhihu, WallstreetCN, etc.).

github/rkiding - External API Usage - 2.8k stars

ThreatsExternal API Usage Rate Limiting

Threat analysis

External API Usage2 findings
Rate Limiting1 finding

Skill info

Namerkiding/alphaear-news
Registrygithub
Version853f09b
PURLpkg:github/RKiding/Awesome-finance-skills@853f09b?skill=alphaear-news
Stars2.8k

Assessments (3)

External API Usage2 findings MEDIUM
MEDIUM

External API Usage via local-llm-review

scripts/content_extractor.py

The ContentExtractor class uses the Jina Reader API (JINA_BASE_URL = 'https://r.jina.ai/') to extract content from URLs. This could pose a risk if the API is not properly secured or if the usage viola
LOW

External API Usage via local-llm-review

scripts/news_tools.py

The NewsNowTools class uses the NewsNow API (BASE_URL = 'https://newsnow.busiyi.world') to fetch news. This could pose a risk if the API is not properly secured or if the usage violates terms of servi
Rate Limiting1 finding LOW
LOW

Rate Limiting via local-llm-review

scripts/content_extractor.py

The ContentExtractor class implements rate limiting, but the logic may not be sufficient to prevent abuse or may not align with the Jina API's actual rate limits.

Badge

Add the Anomity scan badge for alphaear-news to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/rkiding/alphaear-news/)
HTML
<a href="https://anomity.ai/skills/github/rkiding/alphaear-news/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of alphaear-news? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok