google-news-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill functions by having the agent execute a local Python script (scripts/google_news_api.py) with user-supplied arguments, such as search keywords and filters. This is the primary intended operation of the skill and does not involve unauthorized privilege escalation or suspicious shell piping.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves news headlines and metadata from external sources (Google News) and presents them to the agent for processing. This content could potentially contain adversarial text designed to influence the agent's behavior.
  • Ingestion points: News data is fetched from the BrowserAct API in scripts/google_news_api.py and returned as a result string.
  • Boundary markers: The script does not wrap the external content in specific delimiters or safety warnings for the agent.
  • Capability inventory: The skill executes the scripts/google_news_api.py script via the command line to make network requests to the vendor's API.
  • Sanitization: The script does not perform sanitization or filtering of the news headlines or links before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — google-news-api-skill