review-monitoring
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for installation using the
npx skillscommand to add thenexscope-ai/eCommerce-Skillsrepository. These resources are hosted on official vendor-controlled GitHub infrastructure and represent standard deployment practices. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill instructions in
SKILL.mdspecify collecting product ASINs and platform data from user messages. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between user data and instructions.
- Capability inventory: The skill is focused on analytical workflows; it does not contain subprocess calls, network operations for exfiltration, or file-writing capabilities that could be exploited via injection.
- Sanitization: No explicit input validation or sanitization steps are documented.
Audit Metadata