opennews
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
curlandjqto interact with the OpenNews API. These operations are restricted to well-defined vendor endpoints (ai.6551.io) and do not incorporate unvalidated user input into shell commands. - [DATA_EXFILTRATION]: The skill requires an
OPENNEWS_TOKENfor authenticated requests. This token is transmitted only to the vendor's official API endpoint (ai.6551.io) via standard Authorization headers, which is the intended and secure behavior for this service. - [EXTERNAL_DOWNLOADS]: The skill fetches news content and AI-generated summaries from external sources. These downloads are performed through a consolidated vendor API, reducing the attack surface by avoiding direct connections to arbitrary third-party news sites.
Audit Metadata