daily-news-caster
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external news sources that could contain malicious instructions designed to manipulate the agent's output script.
- Ingestion points: External news data fetched from sources like HackerNews or GitHub via the
news-aggregator-skilldependency. - Boundary markers: No delimiters or warnings are used to isolate external content or instruct the agent to ignore instructions embedded within the news.
- Capability inventory: The skill can execute local Python scripts (
fetch_news.py,tts.py), run shell commands (ffmpeg), and write files to the local filesystem. - Sanitization: No evidence of input validation or sanitization for the fetched news items before they are incorporated into the podcast script.
- [COMMAND_EXECUTION]: The skill orchestrates its workflow by executing local Python scripts and system binaries via the command line.
- Evidence: Instructions in Step 2 call
python3to run a news fetching script located atskills/news-aggregator-skill/scripts/fetch_news.py. - Evidence: Instructions in Step 4 call
python3to run a TTS script atskills/tts/scripts/tts.pyand invokeffmpegto concatenate generated audio files. - [EXTERNAL_DOWNLOADS]: The skill initiates network activity through its dependencies to fetch data and process audio.
- Evidence: Fetches real-time news from public sources via the news-aggregator tool.
- Evidence: Communicates with the author's official text-to-speech service at
noiz.aiwhen thenoizbackend is utilized for audio generation.
Audit Metadata