topic-collector

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill directs the agent to gather information from well-known platforms like Twitter, Product Hunt, Reddit, and Hacker News, as well as official sites for AI companies like Anthropic, OpenAI, and Google. This is a standard and safe functionality for a news aggregation tool.
  • [PROMPT_INJECTION]: The skill processes untrusted third-party content retrieved via web search, which introduces an indirect prompt injection surface. The risk is assessed as safe because the skill is limited to content retrieval and formatting, with no access to sensitive data or administrative functions.
  • Ingestion points: Results from WebSearch (SKILL.md)
  • Boundary markers: Absent
  • Capability inventory: None (only text aggregation and formatting)
  • Sanitization: Absent
  • [SAFE]: No evidence of malicious code, data exfiltration, obfuscation, or persistence mechanisms was found in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 11:17 AM
Security Audit — agent-trust-hub — topic-collector