amazon-buy-box

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external marketplace data, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Competitive pricing data, market trends, and seller performance metrics (SKILL.md).\n
  • Boundary markers: Absent; no instructions provided to distinguish external content from system prompts.\n
  • Capability inventory: No custom scripts or tools defined in this specific skill file.\n
  • Sanitization: Absent; no validation protocols specified.\n- [EXTERNAL_DOWNLOADS]: The installation instructions reference fetching the package from the author's GitHub repository (nexscope-ai/Amazon-Skills) via npx.\n- [COMMAND_EXECUTION]: The skill documentation describes how to install the tool globally using the npx package manager command.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:19 AM
Security Audit — agent-trust-hub — amazon-buy-box