linkfox-jiimore-get-niche-info

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (scripts/jiimore_get_niche_info.py and scripts/onboarding.py) to retrieve niche data and handle account authentication. These scripts facilitate interaction with the Jiimore API.\n- [EXTERNAL_DOWNLOADS]: The skill communicates with several vendor-owned domains, including tool-gateway.linkfox.com and api.linkfox.com, to fetch data and manage sessions. These network operations are intrinsic to the skill's functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external market data such as product titles and customer reviews from the Jiimore API. While the skill lacks explicit boundary markers or sanitization logic in the scripts, the instructions guide the agent to present this data in structured formats, which acts as a mitigation for this attack surface.\n- [PERSISTENCE_MECHANISMS]: The skill's documentation includes user-facing instructions to persist API keys by modifying shell configuration files like .bashrc and .zshrc. This is a standard procedure for configuring environment-based credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:02 AM
Security Audit — agent-trust-hub — linkfox-jiimore-get-niche-info