algo-ecom-search

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not provide any scripts or tools that execute on the host system. It outlines best practices for e-commerce search pipelines and provides examples for intent classification and attribute extraction.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a process for analyzing user-provided search queries. While this presents a theoretical attack surface where malicious input could be embedded in search queries, the skill does not grant the agent any dangerous capabilities (like file system writes or network access) based on this input.
  • Ingestion points: User-provided search queries (e.g., 'wireles earphone') processed during the query understanding phase as described in SKILL.md and references/query-pipeline.md.
  • Boundary markers: Not present in the instructional methodology.
  • Capability inventory: No subprocess calls, network operations, or file-write capabilities are defined across any of the files.
  • Sanitization: The methodology explicitly describes normalization and tokenization steps in references/query-pipeline.md which act as sanitization filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — algo-ecom-search