atypica-pulse
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the
@atypica-ai/clipackage from the npm registry, which is a verified resource owned by the skill's vendor. - [COMMAND_EXECUTION]: The skill performs shell command execution through the
atypicaCLI to retrieve trending pulses, detailed stories, and category information. - [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted data from external news and social media sources. 1. Ingestion points:
atypica pulse listandatypica pulse getoutputs inSKILL.md. 2. Boundary markers: None identified. 3. Capability inventory: Subprocess calls to theatypicabinary. 4. Sanitization: None identified.
Audit Metadata