ecommerce-geekbi-temu-search-by-image

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to the vendor's API gateway (api.nexscope.ai) and performs image uploads to provider-managed storage using presigned URLs. These operations are essential for the skill's functionality and target trusted infrastructure.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (geekbi_temu_goods_image_search.py and upload_image.py) to handle API interactions, local caching, and file processing. The scripts use standard libraries and include parameter validation logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests product data (titles, descriptions, etc.) from the Temu marketplace. While this data is externally controlled, the risk of instruction override is minimized by the skill's specific data processing workflow and the underlying agent's safety guardrails.
  • [SAFE]: No malicious behavior, obfuscation, or unauthorized data access was detected. The skill adheres to the vendor's security guidelines for credential management and data handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:13 AM
Security Audit — agent-trust-hub — ecommerce-geekbi-temu-search-by-image