skills/a-canary/arc-skills/shopper/Gen Agent Trust Hub

shopper

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from marketplace listings which could theoretically act as an injection vector.\n
  • Ingestion points: Reads item descriptions, titles, and seller data from api.ebay.com as documented in ebay.md.\n
  • Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to isolate external listing content from the agent's internal logic.\n
  • Capability inventory: The skill executes local Node.js scripts (ebay-item.mjs, ebay.mjs) and performs network requests via fetch as noted in SKILL.md and ebay.md.\n
  • Sanitization: No specific validation or sanitization of external listing content is mentioned before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill documentation provides examples of executing local scripts with user-supplied arguments such as item IDs or URLs.\n
  • Evidence: ebay.md describes the use of node ~/repos/arc-shopper/sources/ebay-item.mjs <itemId | ebay.com/itm/... URL>.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:47 PM
Security Audit — agent-trust-hub — shopper