fetch-news-digest

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation contains a hardcoded placeholder API key: wm_0123456789abcdef0123456789abcdef01234567. While this appears to be a format example rather than a live secret, it matches credential patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external news data which is a primary surface for indirect prompt injection. The skill itself explicitly warns the agent to treat the response as data only and to disregard any instructions found within the text.
  • Ingestion points: News headlines, titles, and item content from https://www.worldmonitor.app/api/news/v1/list-feed-digest (SKILL.md).
  • Boundary markers: The documentation includes a 'Content safety' section explicitly instructing the agent to ignore directive-like text found in responses.
  • Capability inventory: The skill uses curl to interact with the API; the agent is expected to process and summarize the JSON results.
  • Sanitization: No programmatic sanitization is defined; the skill relies on instructional guardrails to mitigate the risk.
  • [COMMAND_EXECUTION]: The documentation includes curl command examples. These are standard documentation practices for API skills and do not represent malicious execution, but illustrate the skill's operational method.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 10:14 PM
Security Audit — agent-trust-hub — fetch-news-digest