skills/nexscope-ai/nexscope-ecommerce-skills/ecommerce-geekbi-temu-search-by-image/Gen Agent Trust Hub
ecommerce-geekbi-temu-search-by-image
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to the vendor's API gateway (api.nexscope.ai) and performs image uploads to provider-managed storage using presigned URLs. These operations are essential for the skill's functionality and target trusted infrastructure.
- [COMMAND_EXECUTION]: The skill executes local Python scripts (geekbi_temu_goods_image_search.py and upload_image.py) to handle API interactions, local caching, and file processing. The scripts use standard libraries and include parameter validation logic.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests product data (titles, descriptions, etc.) from the Temu marketplace. While this data is externally controlled, the risk of instruction override is minimized by the skill's specific data processing workflow and the underlying agent's safety guardrails.
- [SAFE]: No malicious behavior, obfuscation, or unauthorized data access was detected. The skill adheres to the vendor's security guidelines for credential management and data handling.
Audit Metadata