atypica-pulse

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the @atypica-ai/cli package from the npm registry, which is a verified resource owned by the skill's vendor.
  • [COMMAND_EXECUTION]: The skill performs shell command execution through the atypica CLI to retrieve trending pulses, detailed stories, and category information.
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted data from external news and social media sources. 1. Ingestion points: atypica pulse list and atypica pulse get outputs in SKILL.md. 2. Boundary markers: None identified. 3. Capability inventory: Subprocess calls to the atypica binary. 4. Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 03:32 AM