news-to-note

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.
  • Ingestion points: The skill ingests untrusted data from the open web using the WebFetch and WebSearch tools (SKILL.md, section B1).
  • Boundary markers: There are no explicit instructions or delimiters defined to wrap the fetched news content to prevent the agent from following instructions embedded within the news articles.
  • Capability inventory: The agent has broad access to sensitive user information via the search_notes, read_note, and read_section tools, and can modify note content via edit_block (SKILL.md, sections B2, B3, B4).
  • Sanitization: While the instructions specify removing navigation and ads, there is no verification or sanitization of the actual text content to filter out malicious injection payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 06:44 AM
Security Audit — agent-trust-hub — news-to-note