event-tracker

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and the accompanying API map define a clear research workflow using specific, non-privileged tools. Static analysis shows no evidence of obfuscation, remote code execution, persistence mechanisms, or unauthorized privilege escalation.- [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted external sources including Twitter, Reddit, and Google News (ingestion points in SKILL.md). While these platforms present an attack surface for indirect prompt injection, the skill's capabilities are limited to information synthesis and citation (capability inventory: research-only APIs). The absence of high-risk tools such as shell execution, file writing, or generic network requests prevents any theoretical injection from achieving system-level impact. No explicit boundary markers or sanitization steps are defined for the tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — event-tracker