panews-web-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it ingests data from external web pages.
- Ingestion points: The skill performs HTTP GET requests to
https://www.panewslab.comto retrieve Markdown content. - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the incoming web content.
- Capability inventory: No dangerous capabilities such as file system writing, subprocess execution, or administrative tool access are defined within this skill.
- Sanitization: The skill instructions specify returning the Markdown body "as-is," with no explicit sanitization step for the external content.
- [NO_CODE]: The skill is configuration-only and does not include any Python, Node.js, or shell scripts.
- [SAFE]: All network requests are directed to the vendor's official domain (
panewslab.com). No hardcoded credentials, obfuscation, or persistence mechanisms were detected.
Audit Metadata