news-extractor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external news websites (e.g., BBC, CNN, WeChat) as its primary intended function.
  • [DATA_EXFILTRATION]: Contains a hardcoded Twitter guest bearer token in scripts/crawlers/twitter_client.py. This is a standard public token used for anonymous API access to Twitter and does not pose a credential theft risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the web.
  • Ingestion points: Web content is ingested through URLs provided to the crawler scripts (e.g., scripts/extract_news.py).
  • Boundary markers: The skill converts raw HTML into structured JSON and Markdown, effectively separating data from logic.
  • Capability inventory: Performs network requests to fetch articles and writes result files to the local directory.
  • Sanitization: Implements filename sanitization in scripts/extract_news.py using a whitelist of alphanumeric characters, preventing path traversal attacks when saving scraped content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:36 AM