skills/letta-ai/skills/ai-news/Gen Agent Trust Hub

ai-news

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by fetching news descriptions and video transcripts from external, untrusted sources which are then synthesized by the agent. This creates a surface for indirect prompt injection if an external source contains malicious instructions.
  • Ingestion points: Untrusted data enters the agent context via RSS descriptions and YouTube summaries in scripts/fetch-news.ts, and full video transcripts in scripts/fetch-transcript.ts.
  • Boundary markers: The instructions in SKILL.md (Workflow step 2) do not prescribe the use of delimiters (like XML tags or triple backticks) or specific instructions to ignore embedded commands within the fetched content.
  • Capability inventory: The skill has the capability to perform network requests (fetch) and process the resulting data. It also allows the agent to read the output of these fetches to create summaries.
  • Sanitization: The fetch-news.ts script uses a stripHtml function which removes HTML tags and decodes some entities, but it does not perform any validation or filtering to detect or neutralize prompt injection patterns in the text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — ai-news