Yc ReaderSAFE
A collection of skills for AI financial analysis.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Read-only Y Combinator company data skill using the yc-oss/api.
What it does
Fetches Y Combinator company data for startup and venture research — company profiles, batch listings, industry/tag breakdowns, hiring status, and diversity data. Capabilities include:
- Company collections — top companies, all companies, currently hiring, non-profits, diversity data
- Batch lookup — companies by YC batch (e.g., Winter 2025, Summer 2024)
- Industry filter — companies by industry (fintech, healthcare, B2B, etc.)
- Tag filter — companies by tag (AI, developer tools, SaaS, climate, etc.)
- Metadata — overall YC stats, valid batch/industry/tag names
- Client-side search — find companies by name or description via jq filters
This is a read-only data source. The API serves static JSON files — no write operations exist.
Authentication
None required. The API is public and free — just curl the endpoints.
Triggers
- "YC companies in fintech", "top Y Combinator companies", "latest YC batch"
- "YC startups hiring", "find YC companies tagged AI", "W25 batch"
- "Y Combinator portfolio", "startup research", "which YC companies do X"
- Any mention of Y Combinator or YC in context of startup/venture research
Platform
Works on Claude Code and other CLI-based agents. Does not work on Claude.ai — the sandbox restricts network access required for API calls.
Setup
# Choose finance-social-readers when prompted. npx plugins add himself65/finance-skills # Or install just this skill npx skills add himself65/finance-skills --skill yc-reader
See the main README for more installation options.
Prerequisites
curl(pre-installed on macOS and most Linux)jq(for JSON filtering —brew install jqorapt-get install jq)
Reference files
references/api_reference.md— Complete endpoint reference with company schema, all URLs, and research
317cbce031f1OBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npx skills add himself65/finance-skills --skill yc-reader
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: yc-reader
description: >
Look up Y Combinator companies and batches from the public yc-oss API, a static JSON
dataset refreshed daily: company profiles, batch rosters (e.g. W25, S24), companies
by industry or tag, top companies, who is hiring, founder-diversity lists, and
overall YC stats. Use this skill whenever the user asks about YC-backed startups, a
YC batch, YC companies in a sector or tag or that are hiring, the Y Combinator
portfolio, or startup and venture research that draws on YC data. Read-only.
---
# Y Combinator Reader (Read-Only)
Fetches Y Combinator company data from the [yc-oss/api](https://github.com/yc-oss/api), an unofficial open-source API that indexes all publicly launched YC companies. The data is sourced from YC's Algolia search index and updated daily via GitHub Actions.
**This is a read-only data source.** It provides company profiles, batch listings, industry/tag breakdowns, hiring status, and diversity data. No write operations exist — the API serves static JSON files.
**No authentication required.** The API is public and free. Just use `curl` to fetch JSON endpoints.
---
## Step 1: Verify Prerequisites
This skill only needs `curl` (to fetch data) and `jq` (to parse/filter JSON). Both are pre-installed on most systems.
```
!`(command -v curl > /dev/null && echo "CURL_OK" || echo "CURL_MISSING") && (command -v jq > /dev/null && echo "JQ_OK" || echo "JQ_MISSING")`
```
If `JQ_MISSING`, install it:
```bash
# macOS
brew install jq
# Linux (Debian/Ubuntu)
sudo apt-get install jq
```
If `jq` is unavailable, you can still fetch raw JSON with `curl` and parse it inline with Python or other tools — but `jq` makes filtering much easier.
---
## Step 2: Identify What the User Needs
Match the user's request to the appropriate endpoint. See `references/api_reference.md` for full details.
| User Request | Endpoint | Notes |
|---|---|---|
| Overall YC stats | `meta.json` | Company count, batch list, industry/tag lists |
| All companies | `companies/all.json` | Full dataset (~5,700 companies) — large response |
| Top companies | `companies/top.json` | ~91 top-performing YC companies |
| Companies hiring | `companies/hiring.json` | ~1,400 currently hiring |
| Non-profit companies | `companies/nonprofit.json` | YC-backed non-profits |
| Diversity data | `companies/black-founded.json`, `hispanic-latino-founded.json`, `women-founded.json` | Founder diversity |
| Specific batch | `batches/{batch-name}.json` | e.g., `winter-2026.json`, `spring-2026.json`, `fall-2025.json` |
| Single company profile | `batches/{batch-name}/{slug}.json` | e.g., `batches/summer-2009/stripe.json`, `batches/winter-2009/airbnb.json` |
| By industry | `industries/{industry}.json` | e.g., `fintech.json`, `healthcare.json` |
| By tag | `tags/{tag}.json` | e.g., `ai.json`, `developer-tools.json` |
### Batch name format
Batches use `{season}-{year}` format: `winter-2026`, `spring-2026`, `summer-2026`, `fall-2025`. Older batches follow the same pattern back to `summer-2005`. The short form (`w09`, `s21`) also works for the per-company endpoint.
### Industry and tag name format
Use lowercase with hyphens for multi-word names: `real-estate`, `developer-tools`, `machine-learning`.
---
## Step 3: Execute the Request
### Base URL
```
https://yc-oss.github.io/api/
```
### General pattern
```bash
# Fetch and pretty-print
curl -s https://yc-oss.github.io/api/companies/top.json | jq .
# Count companies in a result
curl -s https://yc-oss.github.io/api/batches/winter-2025.json | jq length
# Filter by field (e.g., hiring companies in a batch)
curl -s https://yc-oss.github.io/api/batches/winter-2025.json | jq '[.[] | select(.isHiring == true)]'
# Extract specific fields
curl -s https://yc-oss.github.io/api/companies/top.json | jq '.[] | {name, one_liner, batch, team_size, website}'
# Search by name (case-insensitive)
curl -s https://yc-oss.github.io/api/companies/all.json | jq '[.[] | select(.name | test("stripe"; "i"))]'
```
### Key rules
1. **Use `-s` flag** with curl to suppress progress output
2. **Pipe through `jq`** for readable output and filtering
3. **Avoid fetching `companies/all.json` unless necessary** — it's a large response (~5,700 companies). Prefer more specific endpoints (batches, industries, tags) when possible
4. **Use `jq` select/filter** to narrow results client-side when the API doesn't have a specific endpoint for what the user wants
5. **Batch names are lowercase with hyphens** — `winter-2025` not `Winter 2025` or `W25`
6. **Tag and industry names are lowercase with hyphens** — `developer-tools` not `Developer Tools`
### Common jq filters
| Filter | Purpose |
|---|---|
| `jq length` | Count results |
| `jq '.[0]'` | First company |
| `jq '.[:10]'` | First 10 companies |
| `jq '[.[] \| select(.isHiring == true)]'` | Only hiring companies |
| `jq '[.[] \| select(.status == "Active")]'` | Only active companies |
| `jq '[.[] \| select(.team_size > 100)]'` | Companies with 100+ employees |
| `jq '.[] \| {name, one_liner, batch, website}'` | Select specific fields |
| `jq '[.[] \| select(.name \| test("query"; "i"))]'` | Search by name |
| `jq 'sort_by(-.team_size) \| .[:10]'` | Top 10 by team size |
---
## Step 4: Present the Results
Summarize rather than dump JSON. For each company, give the name, one-liner, batch, team size, status, hiring status (a growth signal), and website. For a batch, lead with its size and notable companies; for an industry or tag, the count and which companies are top or hiring; for research questions, aggregate stats such as counts, common industries, and team-size distribution. Mention that the dataset refreshes daily.
---
## Step 5: Diagnostics
If a request fails:
| Error | Cause | Fix |
|-------|-------|-----|
| `404 Not Found` | Invalid batch, industry, or tag name | Check `meta.json` for valid names |
| Empty array `[]` | No companies match the query | Broaden the search or check spelling |
| `curl: Could not reTrust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
317cbce031f1full audit observations/trust-audit/skill/himself65__yc-reader.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 317cbce031f1 | SAFE | B | 89 | first audit |
Questions
What does the Yc Reader skill do?
A collection of skills for AI financial analysis.
Is Yc Reader safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Yc Reader access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Yc Reader?
Its own instructions reference curl and jq. Dependencies are pinned to exact versions.
Which assistants does Yc Reader work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (317cbce031f1), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.