etsy-print-on-demand

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill does not contain any executable scripts (Python, Node.js, Shell, etc.). It consists entirely of Markdown documentation and metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes capabilities for analyzing user-provided Etsy shop setups and audits. While no code is provided to implement these features in this specific file, any ingestion of external shop data represents a potential attack surface for indirect prompt injection.
  • Ingestion points: User-provided shop details and setup data (implied by "Audit my current setup" prompt).
  • Boundary markers: None present in the skill instructions.
  • Capability inventory: No active capabilities (file-write, network, exec) are defined in this skill file.
  • Sanitization: Not applicable as no processing logic is provided.
  • [SAFE]: All external links and references point to the vendor's official domain (nexscope.ai), representing standard product documentation and marketing links without suspicious redirection or obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:52 AM
Security Audit — agent-trust-hub — etsy-print-on-demand