amazon-product-search-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract and process product data (titles, descriptions, delivery info) from Amazon search results, which is a common vector for indirect prompt injection.
  • Ingestion points: Data enters the agent context via the amazon_product_search_api.py script, which fetches results from the BrowserAct API and prints them to stdout.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved product data as untrusted content or to ignore potential instructions embedded within it.
  • Capability inventory: The skill is authorized to use Python and access the network to communicate with the api.browseract.com endpoint.
  • Sanitization: The Python script prints the raw output from the API without sanitization or filtering, which could allow malicious instructions in product listings to be processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — amazon-product-search-api-skill