amazon-listing-competitor-analysis-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external Amazon product listings, which is an untrusted source.
  • Ingestion Points: The script scripts/amazon_listing_competitor_analysis.py extracts product titles, descriptions, bullet points, and user reviews via the BrowserAct API.
  • Boundary Markers: While the instructions define a clear two-phase workflow, they lack explicit prompt delimiters (e.g., XML tags or unique markers) to isolate the extracted listing content from the agent's instructions.
  • Capability Inventory: The skill is primarily diagnostic. It performs data extraction and text analysis but does not possess high-risk capabilities like local file system modification or command execution based on the ingested data.
  • Sanitization: No explicit sanitization or filtering of the extracted text is performed in the Python script before the content is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-listing-competitor-analysis-skill