news-briefing
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes a Model Context Protocol (MCP) server located at "https://datahub.noxiaohao.com/mcp" to provide its underlying tools. This domain is not identified as part of the official vendor's known infrastructure.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and processes untrusted data from various external news outlets and social media platforms.
- Ingestion points: Content is retrieved from external sources via
news_feedandsocial_trendingtools as described inSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external content as untrusted or to ignore embedded instructions within that content.
- Capability inventory: The skill calls tools that aggregate and synthesize information; while the provided instructions do not show direct shell or file system write access, the agent uses the retrieved data to generate market-relevant briefings.
- Sanitization: There is no evidence of sanitization or validation to prevent malicious payloads within the ingested headlines or social posts from affecting agent behavior or output.
Audit Metadata