product-description-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites via competitor URLs and existing product listings to inform content generation. While this creates a surface for indirect prompt injection, it is central to the skill's primary function.
  • Ingestion points: The skill uses web_fetch to retrieve content from external URLs provided by the user as described in the Mode A and Mode B workflows.
  • Boundary markers: No explicit delimiters or warnings to ignore instructions within the fetched data are present.
  • Capability inventory: The skill utilizes web_fetch and web_search to process external data.
  • Sanitization: The instructions focus on extraction of features and keywords but do not explicitly specify sanitization of the fetched text.
  • [EXTERNAL_DOWNLOADS]: The documentation references external installation commands and resources.
  • The skill mentions installation via npx skills add pointing to the nexscope-ai GitHub organization repositories.
  • It provides links to additional tools and information on the official nexscope.ai domain. All these resources trace back to the verified vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:53 AM
Security Audit — agent-trust-hub — product-description-generator