skills/nexscope-ai/nexscope-ecommerce-skills/ecommerce-chuhaijiang-tiktok-creator/Gen Agent Trust Hub
ecommerce-chuhaijiang-tiktok-creator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes creator metadata and profile information retrieved from the TikTok platform via the NexScope API. While this involves processing untrusted external data, the skill's scripts do not utilize dangerous capabilities like dynamic code evaluation or arbitrary command execution on the received content.
- Ingestion points: API responses from api.nexscope.ai handled by all scripts.
- Boundary markers: None specified in the markdown instructions.
- Capability inventory: Restricted to network communication with vendor endpoints and local file writing within the nexscope/ directory.
- Sanitization: Parameters are validated against a schema before API calls are made.
- [EXTERNAL_DOWNLOADS]: The skill performs network operations to api.nexscope.ai and www.nexscope.ai to fetch creator data and provide help documentation. These domains are official resources belonging to the skill's vendor.
- [COMMAND_EXECUTION]: The skill involves running local Python scripts to interact with the API. The scripts safely parse user-provided JSON parameters using the standard json library and do not use unsafe command shell interpolation.
Audit Metadata