skills/nexscope-ai/nexscope-ecommerce-skills/ecommerce-amazon-niche-info-by-asin/Gen Agent Trust Hub
ecommerce-amazon-niche-info-by-asin
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes product niche data from an external API. This constitutes an indirect prompt injection surface; however, the risk is mitigated by explicit instructions to use
jqfor selective field extraction, preventing large, untrusted payloads from being fully loaded into the conversation context. - [COMMAND_EXECUTION]: The skill executes a Python script to perform API requests and maintain a local cache. The script uses standard libraries and does not accept unsanitized user input for shell execution or dynamic evaluation.
- [EXTERNAL_DOWNLOADS]: The skill communicates with the NexScope proxy API to fetch niche analytical dimensions. This is a documented communication channel necessary for the tool's core functionality.
Audit Metadata