news-shopping
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
agentcashNode.js package from the public NPM registry to access its search functionality. Using the@latesttag ensures the most recent version is used but introduces a dependency on external code updates. - [COMMAND_EXECUTION]: The skill utilizes shell commands through
npx agentcash@latestto perform network operations and fetch data from remote API endpoints hosted atstableenrich.dev. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external search results (news snippets, product descriptions), which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Search results fetched from
https://stableenrich.dev/api/serper/*endpoints (e.g., news, shopping, images) as described inSKILL.md. - Boundary markers: There are no explicit delimiters or system instructions provided to help the agent distinguish between search results and legitimate instructions.
- Capability inventory: The skill has access to shell command execution (
npx) and network access for data retrieval. - Sanitization: No sanitization, filtering, or validation of the fetched external search content is defined in the instructions.
Audit Metadata