ecommerce-amazon-niche-info-by-asin

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product niche data from an external API. This constitutes an indirect prompt injection surface; however, the risk is mitigated by explicit instructions to use jq for selective field extraction, preventing large, untrusted payloads from being fully loaded into the conversation context.
  • [COMMAND_EXECUTION]: The skill executes a Python script to perform API requests and maintain a local cache. The script uses standard libraries and does not accept unsanitized user input for shell execution or dynamic evaluation.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the NexScope proxy API to fetch niche analytical dimensions. This is a documented communication channel necessary for the tool's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:13 AM
Security Audit — agent-trust-hub — ecommerce-amazon-niche-info-by-asin