product-description-generator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites via competitor URLs and existing product listings to inform content generation. While this creates a surface for indirect prompt injection, it is central to the skill's primary function.
- Ingestion points: The skill uses
web_fetchto retrieve content from external URLs provided by the user as described in the Mode A and Mode B workflows. - Boundary markers: No explicit delimiters or warnings to ignore instructions within the fetched data are present.
- Capability inventory: The skill utilizes
web_fetchandweb_searchto process external data. - Sanitization: The instructions focus on extraction of features and keywords but do not explicitly specify sanitization of the fetched text.
- [EXTERNAL_DOWNLOADS]: The documentation references external installation commands and resources.
- The skill mentions installation via
npx skills addpointing to thenexscope-aiGitHub organization repositories. - It provides links to additional tools and information on the official
nexscope.aidomain. All these resources trace back to the verified vendor.
Audit Metadata