filtmall-shopping
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a Node.js wrapper script to execute a bundled CLI runtime for all commerce operations. This is a standard architecture for complex agent skills to maintain consistent behavior across platforms.
- [DATA_EXFILTRATION]: The skill manages session identifiers stored in a local configuration file. While it performs network operations, these are restricted to official vendor domains. The instructions explicitly mandate that the agent must not display session identifiers, tokens, or device codes to the user, providing a layer of protection for user session data.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes data from external product catalogs. 1. Ingestion points: Natural language shopping requests and product descriptions/metadata from the Filtmall API. 2. Boundary markers: The instructions mandate specific Markdown headers but lack explicit delimiters or warnings for external data. 3. Capability inventory: Execution of local scripts and network access to official vendor domains. 4. Sanitization: No explicit programmatic sanitization is described, though the skill mandates strict factual reporting and prohibits the fabrication of product information.
Audit Metadata