linkfox-echotik-list-product
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts (
scripts/echotik_list_product.pyandscripts/onboarding.py) to perform API calls and facilitate user account management. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to vendor-controlled domains including
tool-gateway.linkfox.com,api.linkfox.com, andagent-api.linkfox.com. It also identifies and suggests the installation of well-known third-party packages (requests,qrcode,pillow) for its onboarding and payment functionality. - [PROMPT_INJECTION]: The skill retrieves product data from external API sources, which introduces an indirect prompt injection surface. The instructions do not include specific sanitization steps for this ingested content, though the risk is considered low and inherent to data retrieval tools.
Audit Metadata