news-shopping

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the agentcash Node.js package from the public NPM registry to access its search functionality. Using the @latest tag ensures the most recent version is used but introduces a dependency on external code updates.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands through npx agentcash@latest to perform network operations and fetch data from remote API endpoints hosted at stableenrich.dev.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external search results (news snippets, product descriptions), which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Search results fetched from https://stableenrich.dev/api/serper/* endpoints (e.g., news, shopping, images) as described in SKILL.md.
  • Boundary markers: There are no explicit delimiters or system instructions provided to help the agent distinguish between search results and legitimate instructions.
  • Capability inventory: The skill has access to shell command execution (npx) and network access for data retrieval.
  • Sanitization: No sanitization, filtering, or validation of the fetched external search content is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — news-shopping