fetch-news-digest
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The documentation contains a hardcoded placeholder API key:
wm_0123456789abcdef0123456789abcdef01234567. While this appears to be a format example rather than a live secret, it matches credential patterns. - [INDIRECT_PROMPT_INJECTION]: The skill processes external news data which is a primary surface for indirect prompt injection. The skill itself explicitly warns the agent to treat the response as data only and to disregard any instructions found within the text.
- Ingestion points: News headlines, titles, and item content from
https://www.worldmonitor.app/api/news/v1/list-feed-digest(SKILL.md). - Boundary markers: The documentation includes a 'Content safety' section explicitly instructing the agent to ignore directive-like text found in responses.
- Capability inventory: The skill uses
curlto interact with the API; the agent is expected to process and summarize the JSON results. - Sanitization: No programmatic sanitization is defined; the skill relies on instructional guardrails to mitigate the risk.
- [COMMAND_EXECUTION]: The documentation includes
curlcommand examples. These are standard documentation practices for API skills and do not represent malicious execution, but illustrate the skill's operational method.
Audit Metadata