panews-web-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it ingests data from external web pages.
  • Ingestion points: The skill performs HTTP GET requests to https://www.panewslab.com to retrieve Markdown content.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the incoming web content.
  • Capability inventory: No dangerous capabilities such as file system writing, subprocess execution, or administrative tool access are defined within this skill.
  • Sanitization: The skill instructions specify returning the Markdown body "as-is," with no explicit sanitization step for the external content.
  • [NO_CODE]: The skill is configuration-only and does not include any Python, Node.js, or shell scripts.
  • [SAFE]: All network requests are directed to the vendor's official domain (panewslab.com). No hardcoded credentials, obfuscation, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:37 AM
Security Audit — agent-trust-hub — panews-web-viewer