feed-cpi

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches economic data from the official US Bureau of Labor Statistics website (bls.gov). This is a well-known, reputable government source, and the operation is consistent with the skill's stated purpose of gathering macro-economic data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external URLs to extract inflation metrics. While external content can theoretically be a vector for indirect prompt injection, the skill targets a highly reputable government domain and specifies a structured extraction process for specific numeric fields, which limits the potential attack surface.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file access, hardcoded credentials, or unauthorized network transmissions were detected. The data being fetched is public economic information.
  • [COMMAND_EXECUTION]: The skill does not contain any patterns for executing shell commands, persistent scripts, or administrative actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — feed-cpi