ecommerce-chuhaijiang-tiktok-ads

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of untrusted TikTok ad data.\n
  • Ingestion points: Untrusted data from TikTok ads and creative transcriptions is ingested via endpoints at api.nexscope.ai by the scripts in the scripts/ directory.\n
  • Boundary markers: The skill lacks explicit boundary markers or 'ignore' instructions for the agent when processing externally sourced business data.\n
  • Capability inventory: The skill possesses the capability to perform network requests (urllib.request) and write files to the project's nexscope/ directory.\n
  • Sanitization: API responses are parsed and processed without sanitization or escaping of potentially malicious instructions embedded in ad fields like ad_title or transcription_with_structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:14 AM
Security Audit — agent-trust-hub — ecommerce-chuhaijiang-tiktok-ads