skills/hk-hub/agentskills/aihot/Gen Agent Trust Hub

aihot

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands for the agent to execute at runtime, including curl for data retrieval, jq for parsing JSON responses, and date for computing semantic time windows (e.g., '24 hours ago').
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from the domain aihot.virxact.com. This domain is not associated with the skill author or a known trusted service, representing a third-party dependency for core functionality.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from an external API, which could theoretically contain malicious instructions targeting the AI agent.
  • Ingestion points: Data is ingested via curl from https://aihot.virxact.com/api/public/items and /api/public/daily (SKILL.md).
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to ensure the agent treats the fetched news content as data rather than instructions.
  • Capability inventory: The skill environment permits the use of curl, jq, date, and general shell command execution.
  • Sanitization: There is no mention of sanitizing or escaping the API response content before it is interpolated into the markdown report presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — aihot