amazon-listing-competitor-analysis-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external Amazon product listings, which is an untrusted source.
- Ingestion Points: The script
scripts/amazon_listing_competitor_analysis.pyextracts product titles, descriptions, bullet points, and user reviews via the BrowserAct API. - Boundary Markers: While the instructions define a clear two-phase workflow, they lack explicit prompt delimiters (e.g., XML tags or unique markers) to isolate the extracted listing content from the agent's instructions.
- Capability Inventory: The skill is primarily diagnostic. It performs data extraction and text analysis but does not possess high-risk capabilities like local file system modification or command execution based on the ingested data.
- Sanitization: No explicit sanitization or filtering of the extracted text is performed in the Python script before the content is presented to the agent.
Audit Metadata