ecommerce-geo-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external ecommerce pages, marketplace listings, and crawl evidence, which could contain malicious instructions meant to subvert the agent's behavior.
  • Ingestion points: Data is collected from URLs, page content, and supplied marketplace evidence as described in SKILL.md.
  • Boundary markers: There are no specific instructions or delimiters provided to isolate external content or warn the agent to ignore embedded instructions (absent).
  • Capability inventory: The skill is restricted to diagnostic analysis and report generation in markdown; it does not have access to command execution or network-based exfiltration tools.
  • Sanitization: No sanitization or validation logic for external inputs is mentioned in the skill instructions (absent).
  • [EXTERNAL_DOWNLOADS]: The skill's documentation includes a command to install a package (nexscope-ai/ecommerce-seo-geo-skills) via npx. This is a standard installation step that fetches the skill from the vendor's repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:40 AM
Security Audit — agent-trust-hub — ecommerce-geo-auditor