google-news
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill performs network requests to
google-news.fetcher.sh. These requests are consistent with the skill's stated purpose of fetching news data from the vendor's service and do not represent unauthorized exfiltration. - [CREDENTIALS_UNSAFE]: The documentation references an API key environment variable (
FETCHER_API_KEY) and uses non-sensitive placeholders (bby_live_...) in examples, following safe practices for secret management. - [INDIRECT_PROMPT_INJECTION]: The skill processes external content from news headlines and articles retrieved via API. While this presents a potential surface for indirect prompt injection, it is the primary intended function of the skill.
- [SAFE]: No malicious patterns such as obfuscation, persistence mechanisms, or unauthorized privilege escalation were detected.
Audit Metadata