news-extractor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches content from external news websites (e.g., BBC, CNN, WeChat) as its primary intended function.
- [DATA_EXFILTRATION]: Contains a hardcoded Twitter guest bearer token in
scripts/crawlers/twitter_client.py. This is a standard public token used for anonymous API access to Twitter and does not pose a credential theft risk. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the web.
- Ingestion points: Web content is ingested through URLs provided to the crawler scripts (e.g.,
scripts/extract_news.py). - Boundary markers: The skill converts raw HTML into structured JSON and Markdown, effectively separating data from logic.
- Capability inventory: Performs network requests to fetch articles and writes result files to the local directory.
- Sanitization: Implements filename sanitization in
scripts/extract_news.pyusing a whitelist of alphanumeric characters, preventing path traversal attacks when saving scraped content.
Audit Metadata