ecommerce-geo-score-check
Fail
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Automated scanners flagged a malicious URL (sixstoreys.com) included in the skill's reference materials and sample reports. Additionally, the file 'geo-ai-visibility-report-optimized.html' was identified as malware (FileRepMalware) by reputation scanners.\n- [COMMAND_EXECUTION]: Instructions in 'SKILL.md' explicitly direct the AI agent to write Python code to '/tmp/gen_report.py' and execute it using 'python3' to bypass system-level write protections. This encourages the execution of unvalidated, dynamically generated code in the environment.\n- [DYNAMIC_EXECUTION]: The skill utilizes Node.js 'execSync' to run internal Python CLI tools and further relies on the generation and execution of temporary Python scripts to manage its reporting workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-supplied URLs and external search results, which are then processed by LLM prompts. There are no boundary markers or dedicated sanitization steps to prevent malicious instructions in the external data from influencing the agent's evaluation outcomes.\n- [DATA_EXFILTRATION]: Network communication is performed with 'nexscope.ai' and 'duckduckgo.com'. While these are intended for core functionality, these operations involve transmitting data to non-whitelisted external domains.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata