Security audit
AI News Collector
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only AI news aggregation skill that asks the agent to search public web sources and does not request secrets, privileged access, persistence, or local data access.
Install if you are comfortable with the agent making multiple public web searches and fetches. Verify the README's GitHub repository and external setup-guide link before using manual installation, and be mindful of paywalls, copyright, and site terms when summarizing fetched news content.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
