reg-feed-watcher

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to retrieve information from a wide range of external sources, including official government portals for the US (Federal Register, SEC, FTC), EU (EC Press Corner, EDPB), and China (gov.cn, CAC), as well as reputable industry aggregators.
  • [COMMAND_EXECUTION]: The workflow involves fetching data from various APIs and RSS feeds, which necessitates the use of network-enabled tools or libraries to retrieve content from the URLs listed in the source catalog.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection because it ingests and processes untrusted data from external regulatory feeds.
  • Ingestion points: Regulatory news feeds and announcements fetched from external URLs defined in SKILL.md and references/source-catalog.md.
  • Boundary markers: Absent; there are no specific delimiters or instructions to the model to ignore potential instructions embedded within the fetched regulatory text.
  • Capability inventory: File system access (reading local configuration and writing shared summary reports) and network access (pulling feed updates).
  • Sanitization: Absent; the skill focuses on summarizing and categorizing content without explicit filtering for embedded malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — reg-feed-watcher