amazon-best-selling-products-finder-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from Amazon (product titles, reviews, and descriptions) via the BrowserAct API. Since this content is created by external sellers, it could contain malicious instructions designed to manipulate the agent.
  • Ingestion points: The scripts/amazon_best_selling_products_finder_api.py script retrieves structured product data from an external API and prints it to standard output for the agent to read.
  • Boundary markers: The instructions do not specify boundary markers or include warnings for the agent to ignore instructions embedded within the fetched data.
  • Capability inventory: The skill allows script execution and file system interaction through the agent's shell capabilities.
  • Sanitization: The script prints the API output directly to the console without any sanitization, escaping, or filtering of the external content.
  • [COMMAND_EXECUTION]: The recommended call method in SKILL.md involves passing user-supplied keywords and URLs as command-line arguments to a Python script. If the agent does not correctly escape these strings, it creates a surface for shell command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-best-selling-products-finder-api-skill