newsleopard-api
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill is composed entirely of markdown documentation and reference guides. No executable scripts, binaries, or configuration files are included for the agent to run.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. (1) Ingestion points: Contact list imports (CSV/Text) and message content variables in references/edm-api.md and references/surenotify-api.md. (2) Boundary markers: No explicit instructions are provided to the agent to treat external content as untrusted or to ignore embedded commands. (3) Capability inventory: Interaction with external APIs (api.newsleopard.com, mail.surenotifyapi.com) to send communications via REST endpoints. (4) Sanitization: No sanitization or validation protocols for user-supplied strings are mentioned in the documentation for the agent's implementation.
Audit Metadata