google-news

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill performs network requests to google-news.fetcher.sh. These requests are consistent with the skill's stated purpose of fetching news data from the vendor's service and do not represent unauthorized exfiltration.
  • [CREDENTIALS_UNSAFE]: The documentation references an API key environment variable (FETCHER_API_KEY) and uses non-sensitive placeholders (bby_live_...) in examples, following safe practices for secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content from news headlines and articles retrieved via API. While this presents a potential surface for indirect prompt injection, it is the primary intended function of the skill.
  • [SAFE]: No malicious patterns such as obfuscation, persistence mechanisms, or unauthorized privilege escalation were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:22 PM
Security Audit — agent-trust-hub — google-news