review-monitoring

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for installation using the npx skills command to add the nexscope-ai/eCommerce-Skills repository. These resources are hosted on official vendor-controlled GitHub infrastructure and represent standard deployment practices.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill instructions in SKILL.md specify collecting product ASINs and platform data from user messages.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between user data and instructions.
  • Capability inventory: The skill is focused on analytical workflows; it does not contain subprocess calls, network operations for exfiltration, or file-writing capabilities that could be exploited via injection.
  • Sanitization: No explicit input validation or sanitization steps are documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:53 AM
Security Audit — agent-trust-hub — review-monitoring