ecommerce-amazon-ads-sp-insights-report

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The entry scripts scripts/get_sp_audience_report.py and scripts/get_sp_search_impression_share.py utilize subprocess.run to execute a local dependency checker script scripts/check_auth_dependency.py. This execution is used to verify the presence of a required authorization skill before proceeding with API operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external CSV reports fetched from the Amazon Ads API. In scripts/reporting_v1_workflow.py, the _preview_csv function reads these files using csv.DictReader and returns the content as a preview to the agent. This represents an indirect prompt injection surface if the external data contains malicious instructions.\n
  • Ingestion points: _preview_csv in scripts/reporting_v1_workflow.py reads data from files saved in nexscope/.\n
  • Boundary markers: The skill does not employ specific delimiters to isolate the CSV data from the agent's instructions.\n
  • Capability inventory: The skill performs authenticated network requests to api.nexscope.ai and writes results to the local filesystem.\n
  • Sanitization: No specific content sanitization is performed on the CSV values beyond standard CSV parsing.\n- [DATA_EXFILTRATION]: The skill communicates with api.nexscope.ai (Vendor Resource) to proxy Amazon Ads requests. It includes logic in scripts/reporting_v1_workflow.py (_redact_presigned_urls) to remove sensitive download parameters from logs and responses. Additionally, _reject_sensitive_values prevents the inclusion of Amazon Advertising API secrets or tokens in the skill's request parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:13 AM
Security Audit — agent-trust-hub — ecommerce-amazon-ads-sp-insights-report