profit-margin-calculator-amazon

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection through data ingestion, though no exploitable capabilities were found during analysis.\n
  • Ingestion points: User-provided JSON strings via sys.argv[1] and CSV content via parse_csv in scripts/calculator.py.\n
  • Boundary markers: None present; the skill treats all input as data for calculation.\n
  • Capability inventory: None identified; there are no subprocess calls, network operations, or file-writing functions in any script.\n
  • Sanitization: Input values for cost parameters are explicitly cast to floats, providing validation for numeric fields.\n- [SAFE]: The skill's primary function is local mathematical calculation. No evidence of credential theft, data exfiltration, or malicious command execution was found. All external resources belong to the author's official infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 11:27 AM
Security Audit — agent-trust-hub — profit-margin-calculator-amazon