news-digest
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from RSS and Atom feeds, which is a known attack surface for indirect prompt injection. The skill implements several defense-in-depth measures:
- Ingestion points: External data is fetched from public feeds via the FEEDS list in scripts/main.py.
- Boundary markers: The system prompt explicitly instructs the agent to treat feed content as data only and to ignore any embedded instructions or injection attempts.
- Capability inventory: The agent has access to terminal and file_editor tools during the summarization process.
- Sanitization: Content is sanitized using the strip_html function in scripts/main.py and truncated to prevent large-scale injection payloads.
- [COMMAND_EXECUTION]: Standard system commands (curl, python3, tar) are used during the setup workflow in SKILL.md for feed validation and script packaging. These are typical administrative tasks for setting up an automation.
- [EXTERNAL_DOWNLOADS]: The skill fetches data from user-configured RSS and Atom feeds. The fetcher in scripts/main.py enforces a 4 MB size limit and restricts protocols to http and https to prevent resource exhaustion and local file exposure.
Audit Metadata