ecommerce-chuhaijiang-tiktok-ads
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of untrusted TikTok ad data.\n
- Ingestion points: Untrusted data from TikTok ads and creative transcriptions is ingested via endpoints at
api.nexscope.aiby the scripts in thescripts/directory.\n - Boundary markers: The skill lacks explicit boundary markers or 'ignore' instructions for the agent when processing externally sourced business data.\n
- Capability inventory: The skill possesses the capability to perform network requests (
urllib.request) and write files to the project'snexscope/directory.\n - Sanitization: API responses are parsed and processed without sanitization or escaping of potentially malicious instructions embedded in ad fields like
ad_titleortranscription_with_structure.
Audit Metadata