uzi
A-share, Hong Kong, and US stock analysis skill for deep research, quick scans, investor panel review, hot-money/LHB analysis, trap detection, valuation, IC memos, and Bloomberg-style HTML reports.
How do I install this agent skill?
npx skills add https://github.com/wbh604/uzi-skill --skill uziIs this agent skill safe to install?
- Gen Agent Trust Hubfail
The skill facilitates in-depth financial analysis but implements several high-risk patterns, primarily unverified remote code execution. It provides an 'install-hermes.sh' script via a piped bash command (curl | bash) and frequently instructs the AI agent to execute arbitrary Python code blocks for system updates and data backfilling. Furthermore, it incorporates an external data source domain flagged as a phishing risk and automates the download of third-party binaries like Chromium and Cloudflared. The ingestion of qualitative data from web searches also creates a significant surface for indirect prompt injection.
- Socketwarn
5 alerts: gptAnomaly, gptSecurity
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
UZI Skill Root
This root file is the top-level entry for agents that expect a SKILL.md at the repository root.
Use the narrowest matching workflow:
- Full stock research, valuation, IC memo, initiation, catalysts, earnings review, or HTML report:
read
skills/deep-analysis/SKILL.md. - Investor jury, "which investors would buy", panel-only voting, or persona review:
read
skills/investor-panel/SKILL.md. - Hot-money, LHB, seat recognition, or A-share short-term trader analysis:
read
skills/lhb-analyzer/SKILL.md. - Trap detection, pump-and-dump checks, "teacher/group/friend recommended this stock", or safety review:
read
skills/trap-detector/SKILL.md. - Command-specific requests:
read the matching file under
commands/.
Default Execution
From the repository root:
python3 run.py <ticker> --no-browser
For remote/mobile reports:
python3 run.py <ticker> --remote
For a single investor school, such as A-share hot-money:
python3 run.py <ticker> --school F --no-browser
Agent Rules
- Treat scripts as data and scoring tools, not as final analyst judgment.
- Do not invent numbers. Use script outputs, cached JSON, or current public evidence.
- For serious deep-analysis requests, complete the agent review loop described in
skills/deep-analysis/SKILL.mdbefore final report assembly. - For hot-money analysis, apply LHB seat matching and
is_in_range()before making a short-term judgment. - For trap detection, scan all eight signals and include concrete evidence when risk is non-trivial.
- For report template or UI changes, update tests, version metadata, and release notes together.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/wbh604/uzi-skill/uzi">View uzi on skillZs</a>