competitive-pricing-strategy
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are purely analytical and advisory. It contains no hidden code, obfuscation, or instructions to bypass security boundaries.
- [EXTERNAL_DOWNLOADS]: The skill provides installation instructions via
npxtargeting the vendor's own package repository (nexscope-ai/eCommerce-Skills). These references are consistent with the author identity and are not suspicious. - [DATA_EXFILTRATION]: The skill requests detailed unit economics (COGS, freight, fees) to calculate price floors. This is essential for the stated purpose. There are no instructions to transmit this sensitive business data to unauthorized external endpoints. All URLs point to the official vendor domain at
nexscope.ai. - [INDIRECT_PROMPT_INJECTION]: The workflow includes steps to analyze competitor offers via source URLs. This represents a potential surface for indirect prompt injection if an attacker-controlled page contains hidden instructions. However, the skill lacks the high-risk capabilities (such as shell access, file-system modification, or network requests to arbitrary domains) necessary to exploit such an injection effectively. This is an inherent risk of data-ingestion skills and is handled within safe parameters here.
Audit Metadata