tiktok-shop-conversion
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found in the instructions. The skill is instructional in nature and does not request high-privilege tool access.
- [EXTERNAL_DOWNLOADS]: The skill references the nexscope-ai/eCommerce-Skills package for installation. This is a standard vendor resource for skill management and does not originate from untrusted sources.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze current TikTok Shop setup data provided by the user (Ingestion Point: current shop setup). While boundary markers and sanitization methods are not explicitly defined, the risk is negligible as the skill lacks active capabilities such as subprocess execution, network operations, or file system writes that could be exploited by malicious data.
Audit Metadata