ecommerce.shopee-product-detail
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes product names, descriptions, and other listing details from Shopee, which constitute external, untrusted content. This creates a surface for indirect prompt injection where malicious instructions could be embedded in a listing to influence agent behavior during analysis.
- Ingestion points: The script
scripts/shopee_product_detail.pyfetches listing data from the Shopee API through the Nexscope research proxy. - Boundary markers: The instructions in
SKILL.mddo not include explicit delimiters or specific instructions for the agent to ignore instructions found within the ingested product content. - Capability inventory: The skill possesses network access (via
urllib) and file-writing capabilities (to thenexscope/logging directory). - Sanitization: The skill parses the API response as JSON and includes instructions to redact credentials from output, but it does not perform specific sanitization on natural language fields (like product descriptions) to prevent injection.
- [COMMAND_EXECUTION]: The skill executes a Python script,
scripts/shopee_product_detail.py, which is the primary mechanism for interacting with the Nexscope research API. The script is bundled with the skill and uses standard libraries. - [DATA_EXFILTRATION]: The skill communicates with the vendor's research proxy at a URL defined by the
NEXSCOPE_PROXY_BASEenvironment variable. It uses theNEXSCOPE_API_KEYenvironment variable for authentication. This is standard functionality for accessing the vendor's specific research services. - [DATA_EXFILTRATION]: The Python script writes API responses and diagnostic logs to a local directory named
nexscope/within the current working directory or the user's home folder. This behavior is documented and used for caching and session management.
Audit Metadata