amazon-competitor-analyzer
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external product data, such as titles, features, and reviews, from the Amazon API and writes this untrusted content directly into Markdown and CSV reports.
- Ingestion points: The
get_resultsmethod inamazon_competitor_analyzer.pyretrieves raw data from theapi.browseract.comendpoint. - Boundary markers: The generated reports do not use specific delimiters or warnings to isolate untrusted external content from the analysis results.
- Capability inventory: The skill utilizes network access and local file system write operations within
amazon_competitor_analyzer.pyto create analysis documents. - Sanitization: While ASIN inputs are strictly validated for format (10 alphanumeric characters), the product content returned by the API is interpolated into output files without escaping or sanitization, creating a potential vector for indirect injection attacks targeting report viewers.
- [EXTERNAL_DOWNLOADS]: The skill relies on the well-known
requestslibrary for network communication andpython-dotenvfor managing environment variables. - Evidence: Dependencies are specified in the
SKILL.mdfile and imported inamazon_competitor_analyzer.pyto facilitate API interactions and secure configuration loading.
Audit Metadata