competitive-pricing-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are purely analytical and advisory. It contains no hidden code, obfuscation, or instructions to bypass security boundaries.
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions via npx targeting the vendor's own package repository (nexscope-ai/eCommerce-Skills). These references are consistent with the author identity and are not suspicious.
  • [DATA_EXFILTRATION]: The skill requests detailed unit economics (COGS, freight, fees) to calculate price floors. This is essential for the stated purpose. There are no instructions to transmit this sensitive business data to unauthorized external endpoints. All URLs point to the official vendor domain at nexscope.ai.
  • [INDIRECT_PROMPT_INJECTION]: The workflow includes steps to analyze competitor offers via source URLs. This represents a potential surface for indirect prompt injection if an attacker-controlled page contains hidden instructions. However, the skill lacks the high-risk capabilities (such as shell access, file-system modification, or network requests to arbitrary domains) necessary to exploit such an injection effectively. This is an inherent risk of data-ingestion skills and is handled within safe parameters here.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 05:20 AM
Security Audit — agent-trust-hub — competitive-pricing-strategy