linkfox-echotik-list-product

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts (scripts/echotik_list_product.py and scripts/onboarding.py) to perform API calls and facilitate user account management.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to vendor-controlled domains including tool-gateway.linkfox.com, api.linkfox.com, and agent-api.linkfox.com. It also identifies and suggests the installation of well-known third-party packages (requests, qrcode, pillow) for its onboarding and payment functionality.
  • [PROMPT_INJECTION]: The skill retrieves product data from external API sources, which introduces an indirect prompt injection surface. The instructions do not include specific sanitization steps for this ingested content, though the risk is considered low and inherent to data retrieval tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:44 PM
Security Audit — agent-trust-hub — linkfox-echotik-list-product