panews
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on a local Node.js script (
scripts/cli.mjs) to perform all data retrieval and platform interaction tasks. The agent is instructed to run commands likenode cli.mjs search-articlesandnode cli.mjs get-articleto fetch information from the PANews platform. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, which could be exploited to influence agent behavior through indirect prompt injection.
- Ingestion points: The skill retrieves full article content in
workflow-read-article.mdand community-generated comments inworkflow-topics.md. - Boundary markers: There are no explicit instructions or delimiters defined to isolate external data from the agent's internal reasoning or to warn the agent to ignore instructions embedded in the news content.
- Capability inventory: The agent has the capability to execute local CLI commands (
node scripts/cli.mjs) which are used to fetch and display the external data. - Sanitization: The workflows do not specify any sanitization, filtering, or validation of the retrieved text before it is presented to the agent for summarization or analysis.
Audit Metadata