news-aggregator
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external, untrusted news sources which could contain adversarial instructions intended to influence the agent's behavior.
- Ingestion points: External data is retrieved using the
google_news_bulk_articles,tavily_search, andexa_searchtools as listed inSKILL.md. - Boundary markers: The workflow does not include instructions to use delimiters or to treat tool outputs as untrusted information.
- Capability inventory: The skill uses
sandbase_call_toolto access external web content. - Sanitization: There are no instructions to sanitize, escape, or filter the content retrieved from search results before it is processed.
Audit Metadata