amazon-backend-keywords

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to install components using npx skills add nexscope-ai/Amazon-Skills. This command fetches resources from the author's official GitHub organization, which is a standard distribution method for this vendor's tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as product ASINs, category information, and current keyword lists to generate optimization strategies. It lacks explicit instructions for the agent to use delimiters or sanitization logic when handling this untrusted input.
  • Ingestion points: User-provided search terms, product descriptions, and keyword lists referenced in SKILL.md examples.
  • Boundary markers: Absent; there are no instructions to encapsulate user data or ignore embedded instructions within that data.
  • Capability inventory: The skill focus is on text analysis and strategy generation; it does not request high-privilege tool access in its frontmatter.
  • Sanitization: No validation or filtering steps are specified for user-provided keyword strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:19 AM
Security Audit — agent-trust-hub — amazon-backend-keywords