ecommerce-chuhaijiang-tiktok-video

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill uses standard API integration patterns and restricts data access to public market intelligence.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from TikTok (descriptions, creator nicknames, and video reviews).
  • Ingestion points: Data is ingested through the execution of search, detail, related products, and reviews scripts located in the scripts/ directory.
  • Boundary markers: The skill instructions do not specify explicit delimiters or markers to isolate the retrieved external content from the agent's internal system prompt.
  • Capability inventory: The skill scripts have capabilities limited to writing JSON data files into a local nexscope/ subdirectory and making network POST requests to the vendor's official domain (api.nexscope.ai).
  • Sanitization: The skill performs standard JSON parsing but does not include specific safety filtering or sanitization of text content before it is processed by the agent. The risk is considered minimal due to the narrow scope of the skill's capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:13 AM
Security Audit — agent-trust-hub — ecommerce-chuhaijiang-tiktok-video