amazon-buy-box-monitor-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script (scripts/amazon_buy_box_monitor_api.py) which uses the requests library to communicate with the BrowserAct API.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Amazon product pages via a third-party API and prints the results directly to the terminal for the agent to process.
    • Ingestion points: Data is fetched in scripts/amazon_buy_box_monitor_api.py from api.browseract.com (which proxies Amazon content).
    • Boundary markers: No delimiters or protective warnings are used when printing the external data.
    • Capability inventory: The agent has the ability to execute Python scripts and perform network requests.
    • Sanitization: The external content is printed as a raw string or JSON without filtering or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-buy-box-monitor-api-skill