aeon-narrative-tracker

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: Comprehensive analysis of the SKILL.md and catalog.json files confirms that the skill is focused on narrative analysis and market tracking without any indicators of malicious intent or hidden functionality.
  • [NO_CODE]: The skill consists exclusively of logical instructions, formatting rules, and configuration metadata. It does not include executable scripts, binary files, or automated build steps, significantly reducing the risk of code-based attacks.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by ingesting data from external sources such as xAI x_search and broader web platforms. However, since the skill's functionality is limited to formatting and summarizing this data for the user, the risk is negligible as it lacks the capabilities to perform sensitive system operations or data exfiltration.
  • [CREDENTIALS_UNSAFE]: The skill mentions the use of an optional XAI_API_KEY and other social-source credentials. These are referenced neutrally as configuration requirements for standard data access and are not hardcoded or handled in an insecure manner.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 02:11 PM
Security Audit — agent-trust-hub — aeon-narrative-tracker