hackernews-frontpage

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper library _lib/browse-client.ts executes the git command via spawnSync to identify the project's root directory. This is used solely to locate a local configuration file for the automation daemon.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-generated content from Hacker News, which acts as a potential surface for indirect prompt injection if the output is processed by an AI agent without further validation.
  • Ingestion points: The skill fetches the Hacker News front page (https://news.ycombinator.com/) in script.ts.
  • Boundary markers: Absent; the scraped data is returned as a plain JSON array of objects.
  • Capability inventory: The skill has access to browser automation tools (navigation, clicking, snapshots), local file system reading for its own configuration, and basic command execution (git).
  • Sanitization: Extracted titles and URLs are cleaned by stripping HTML tags and decoding HTML entities in script.ts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:04 PM
Security Audit — agent-trust-hub — hackernews-frontpage