public-relations
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides shell commands in
references/newsjacking.mdusingcurl,jq, andxmllintto fetch and parse data from public APIs. It also recommends installingjqusing the Homebrew package manager.\n- [EXTERNAL_DOWNLOADS]: The skill fetches public RSS and JSON data from well-known services, including Google News, Reddit, and Algolia (Hacker News), to assist with media monitoring and research.\n- [PROMPT_INJECTION]: The skill processes untrusted data from external news and social platforms. While this represents a surface for indirect prompt injection, the risk is mitigated by the skill's specific focus on generating professional pitches and the lack of high-privilege capabilities.\n- [SAFE]: The skill follows standard agent practices for managing context by reading from and writing to files within the.agents/directory. No unauthorized persistence, credential harvesting, or obfuscation was found.
Audit Metadata