ecommerce-geekbi-temu-product

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external market data from Temu (titles, descriptions, and categories) which could contain embedded instructions intended to influence the agent's behavior.
  • Ingestion points: External product data entering via NexScope API responses in scripts/geekbi_temu_goods_search.py and scripts/geekbi_temu_goods_detail.py.
  • Boundary markers: The skill instructions in SKILL.md and references/api.md explicitly guide the agent to distinguish between the NexScope transport envelope and the nested business data.
  • Capability inventory: The skill has network access through urllib.request and the ability to write session data and logs to the local file system.
  • Sanitization: All scripts perform rigorous parameter validation against a predefined JSON schema before making requests, and the agent is instructed to summarize results using specific fields rather than returning raw unvalidated content.
  • [EXTERNAL_DOWNLOADS]: Fetches market research data and product information from the NexScope API service (api.nexscope.ai), which is the official platform for the skill vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:13 AM
Security Audit — agent-trust-hub — ecommerce-geekbi-temu-product