linkfox-sorftime-walmart-category-market

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Python scripts (scripts/sorftime_walmart_category_market.py and scripts/onboarding.py) to interface with the LinkFox API gateway and manage account settings. This is standard implementation for this category of tool.
  • [EXTERNAL_DOWNLOADS]: The scripts communicate exclusively with domains owned by the vendor (linkfox.com, linkfox-ai.com) to perform e-commerce data lookups, handle SMS-based login, and manage billing for API credits. These are recognized as legitimate vendor resources.
  • [DATA_EXPOSURE]: The skill requires environment variables such as LINKFOX_AGENT_API_KEY for authentication. The scripts are designed to read these variables to authorize requests to the API gateway. This is the documented and expected method for managing secrets in this environment.
  • [PERSISTENCE]: The onboarding documentation provides instructions for users to manually add API keys to their shell configuration files (e.g., .zshrc, .bashrc). This is a standard developer configuration step and is not an automated or hidden persistence mechanism.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured e-commerce data (category trees and market reports) from the Walmart marketplace. The instructions guide the agent to store this data in files and use tools like jq to extract information, minimizing the risk of the model directly executing instructions embedded in the external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:04 PM
Security Audit — agent-trust-hub — linkfox-sorftime-walmart-category-market