public-relations

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands in references/newsjacking.md using curl, jq, and xmllint to fetch and parse data from public APIs. It also recommends installing jq using the Homebrew package manager.\n- [EXTERNAL_DOWNLOADS]: The skill fetches public RSS and JSON data from well-known services, including Google News, Reddit, and Algolia (Hacker News), to assist with media monitoring and research.\n- [PROMPT_INJECTION]: The skill processes untrusted data from external news and social platforms. While this represents a surface for indirect prompt injection, the risk is mitigated by the skill's specific focus on generating professional pitches and the lack of high-privilege capabilities.\n- [SAFE]: The skill follows standard agent practices for managing context by reading from and writing to files within the .agents/ directory. No unauthorized persistence, credential harvesting, or obfuscation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:30 AM
Security Audit — agent-trust-hub — public-relations