newegg-pc-compatibility-checker

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the bash tool to execute curl commands. These commands are restricted to interacting with specific JSON-RPC endpoints for PC hardware compatibility checks and product searches.
  • [EXTERNAL_DOWNLOADS]: The skill connects to apis-e111.newegg.org and apis.newegg.com to fetch product data and compatibility verdicts. These are official vendor-owned domains corresponding to the author 'neweggai'.
  • [PROMPT_INJECTION]: The skill ingests hardware data and error messages from external APIs, creating a potential surface for indirect instructions. 1. Ingestion points: Product search results and compatibility reasonTraces are retrieved from external endpoints. 2. Boundary markers: None are present to separate the external data from the skill's instructions. 3. Capability inventory: The skill uses the bash tool for network operations via curl. 4. Sanitization: There are no explicit sanitization or filtering steps for the incoming API data before it is presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 11:33 AM