hn
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
xCLI tool (a vendor resource) to interact with Hacker News via commands such asx hnandx hn :: <query>. - [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection because it summarizes untrusted data from Hacker News posts and comments.
- Ingestion points: Hacker News content retrieved via the
x hncommand (SKILL.md). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are provided in the skill text.
- Capability inventory: Terminal-based navigation and display of stories (SKILL.md).
- Sanitization: Not specified in the skill documentation.
- [NO_CODE]: This skill consists of markdown instruction files only and does not include any scripts or executable code.
Audit Metadata