news-to-note
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.
- Ingestion points: The skill ingests untrusted data from the open web using the
WebFetchandWebSearchtools (SKILL.md, section B1). - Boundary markers: There are no explicit instructions or delimiters defined to wrap the fetched news content to prevent the agent from following instructions embedded within the news articles.
- Capability inventory: The agent has broad access to sensitive user information via the
search_notes,read_note, andread_sectiontools, and can modify note content viaedit_block(SKILL.md, sections B2, B3, B4). - Sanitization: While the instructions specify removing navigation and ads, there is no verification or sanitization of the actual text content to filter out malicious injection payloads.
Audit Metadata