google-news-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it ingests and processes untrusted news data from the web.
  • Ingestion points: External news articles and media content are retrieved using the google_news_bulk_articles tool, as described in references/sandbase-api-map.md.
  • Boundary markers: The skill does not currently implement specific delimiters or 'ignore' instructions to isolate processed news content from the agent's control logic.
  • Capability inventory: The skill utilizes the sandbase_call_tool capability, which provides a gateway for tool execution based on the results of news searches.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation steps for the content returned by external news sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — google-news-research