ai-news-digest

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (fetch_ai_news.py and fetch_github_ai_trending.py) to perform data aggregation tasks. These scripts are managed locally within the skill's folder and handle data retrieval and formatting.
  • [EXTERNAL_DOWNLOADS]: The skill connects to various reputable external sources to fetch news data. This includes RSS/Atom feeds from organizations like OpenAI, Google, and Microsoft, as well as the GitHub API and GitHub Trending page. These network operations are core to the skill's functionality and target well-known services.
  • [PROMPT_INJECTION]: The skill handles data from external news feeds and GitHub repository descriptions. While this creates an inherent surface for indirect prompt injection, the scripts implement HTML sanitization (stripping script and style tags), and the targeted sources are established technology news outlets and platforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:46 PM
Security Audit — agent-trust-hub — ai-news-digest