amazon-listing-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled bash script, scripts/fetch-listing.sh, to automate the retrieval of product metadata from Amazon. This script is invoked to support the audit and optimization workflows.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests using curl to fetch product data from various official Amazon marketplace domains (e.g., amazon.com, amazon.co.uk, amazon.de). These operations are consistent with the skill's stated purpose of Amazon listing optimization.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external Amazon listings, which could contain adversarial instructions hidden in product titles or descriptions.
  • Ingestion points: Data is fetched from Amazon product pages via the fetch-listing.sh script, which extracts titles, bullet points, and descriptions.
  • Boundary markers: The skill instructions do not specify explicit delimiters or "ignore instructions" tags when processing the fetched listing content.
  • Capability inventory: The skill environment allows for shell script execution (fetch-listing.sh) and network operations via curl.
  • Sanitization: The fetch-listing.sh script uses grep and sed to isolate specific listing elements, which provides a layer of structural filtering before the data is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:20 PM
Security Audit — agent-trust-hub — amazon-listing-optimization