amazon-competitor-analyzer

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external product data, such as titles, features, and reviews, from the Amazon API and writes this untrusted content directly into Markdown and CSV reports.
  • Ingestion points: The get_results method in amazon_competitor_analyzer.py retrieves raw data from the api.browseract.com endpoint.
  • Boundary markers: The generated reports do not use specific delimiters or warnings to isolate untrusted external content from the analysis results.
  • Capability inventory: The skill utilizes network access and local file system write operations within amazon_competitor_analyzer.py to create analysis documents.
  • Sanitization: While ASIN inputs are strictly validated for format (10 alphanumeric characters), the product content returned by the API is interpolated into output files without escaping or sanitization, creating a potential vector for indirect injection attacks targeting report viewers.
  • [EXTERNAL_DOWNLOADS]: The skill relies on the well-known requests library for network communication and python-dotenv for managing environment variables.
  • Evidence: Dependencies are specified in the SKILL.md file and imported in amazon_competitor_analyzer.py to facilitate API interactions and secure configuration loading.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-competitor-analyzer