amazon-search-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process product-specific data, such as ASINs and listing descriptions, which provides a standard surface for indirect prompt injection.
- Ingestion points: Processes user-provided product details, listing content, and keyword data as defined in the 'Usage Examples' and 'Output Format' sections of
SKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands in the input data are defined in the instructions.
- Capability inventory: The skill is composed entirely of markdown instructions and does not possess capabilities for subprocess execution, file system modification, or automated network requests.
- Sanitization: The skill does not implement explicit sanitization or validation of external input data.
- [EXTERNAL_DOWNLOADS]: The skill provides installation instructions that reference a remote repository hosted by the vendor.
- Evidence: The installation command
npx skills add nexscope-ai/Amazon-Skillspoints to the nexscope-ai vendor repository on GitHub. - [NO_CODE]: The provided skill consists exclusively of markdown documentation and configuration without any accompanying scripts or executable logic.
Audit Metadata