market-news-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves gathering news and data from external websites using WebSearch and WebFetch. This exposes the agent to indirect prompt injection, where third-party web content could contain hidden instructions designed to manipulate the agent's behavior.
- Ingestion points: The skill explicitly instructs the agent to run broad and specific web searches (e.g., military actions, coups, economic data) and fetch content from various URLs (SKILL.md Step 1).
- Boundary markers: There are no instructions for the agent to use delimiters or sanitization techniques to separate external content from its internal reasoning or to ignore embedded instructions in the fetched data.
- Capability inventory: The skill is scoped to analysis and report generation in markdown format. It does not exhibit dangerous capabilities such as direct shell command execution, arbitrary file writing to sensitive locations, or unauthorized network exfiltration of local credentials.
- Sanitization: The instructions lack guidance on filtering or validating the integrity of the information fetched from the web before processing it for the final report.
Audit Metadata