amazon-product-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a standalone Python script (amazon_product_api.py) to perform its primary function. The script utilizes the requests library to communicate with the BrowserAct API, following a standard workflow of starting a task, polling for completion, and retrieving results.
  • [DATA_EXFILTRATION]: The skill transmits search parameters and the BROWSERACT_API_KEY to api.browseract.com. This represents normal interaction with the vendor's provided services and does not indicate malicious exfiltration of sensitive local data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and prints product data extracted from Amazon. While this content originates from an external source and could theoretically contain adversarial text, the skill's purpose is data extraction rather than execution, and it does not grant the processed content any privileged access to the underlying system.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-product-api-skill