consume-feed
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from external RSS feeds and stores it in a memory database. \n
- Ingestion points: Titles and summaries from RSS feeds are ingested in sources/rss.py. \n
- Boundary markers: There are no specific delimiters or instructions to the agent to treat ingested feed content as untrusted. \n
- Capability inventory: The stored content is added to a 'memory' system via a Unix socket (/run/user/1000/embry/memory.sock) using the learn command, which is intended to influence future agent decisions. \n
- Sanitization: Basic HTML stripping is performed in util/text.py, but it does not sanitize against malicious instructions in the text. \n- [EXTERNAL_DOWNLOADS]: The skill performs automated network requests to fetch RSS feeds from URLs defined in user-managed configuration files. \n
- Evidence: util/http.py uses the httpx library to download XML content from external sources. \n- [COMMAND_EXECUTION]: The skill uses command execution for internal testing and environment management. \n
- Evidence: sanity/test_retry_logic.py uses subprocess.Popen to execute a local mock server script (mock_server.py) for testing network resilience. This is a controlled use of process spawning limited to the sanity check phase.
Audit Metadata