ecommerce-chuhaijiang-tiktok-shop
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Chuhaijiang and NexScope APIs, which introduces a potential surface for indirect prompt injection if the retrieved content contains adversarial instructions.
- Ingestion points: Data is fetched from the NexScope API gateway (e.g.,
https://api.nexscope.ai/api/v1/tools/research/chuhaijiang/sellers/search) via the various entry scripts. - Boundary markers: The scripts do not utilize explicit boundary markers or "ignore instructions" warnings when presenting the retrieved business data to the agent context.
- Capability inventory: The skill possesses the capability to perform network requests to the vendor API and write JSON response data to the local
nexscope/directory within the project workspace. - Sanitization: While request parameters are strictly validated using type and regex checks in
validate_params, the content of API responses is not sanitized for natural language instructions before being passed to the agent. - [COMMAND_EXECUTION]: The skill utilizes Python scripts to interface with the NexScope API. These scripts are executed via the command line and take JSON-formatted arguments.
- Evidence: The scripts use
sys.argvto capture input andjson.loadsfor parsing, which is a standard and controlled method for agent-to-script communication. Input validation is performed before processing.
Audit Metadata