skills/nexscope-ai/nexscope-ecommerce-skills/ecommerce.tiktok-batch-product-detail/Gen Agent Trust Hub
ecommerce.tiktok-batch-product-detail
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script to perform API requests. The script (
scripts/echotik_batch_product_detail.py) usesurllib.requestto interact with the Nexscope proxy and processes JSON input. It implements local caching and writes data to structured directories within the current project or user home directory, falling back to temporary storage only if these are unavailable. - [INDIRECT_PROMPT_INJECTION]: The skill processes external product data from TikTok, including descriptions (
descDetail) that may contain HTML or long text. While this presents a surface for indirect injection, the instructions include specific display rules to summarize long content rather than performing a raw dump, and the analysis is scoped to numeric metrics like sales and GMV, which reduces the risk. - Ingestion points: External TikTok product data retrieved via the
batchProductDetailendpoint inreferences/api.md. - Boundary markers: The instructions in
SKILL.mdadvise against loading the entire JSON into context and suggest usingjqfor extraction. - Capability inventory: The skill can perform network requests to the Nexscope proxy and write JSON files to the local disk.
- Sanitization: The platform envelope translates content and removes sensitive provider-level error fields before passing data to the agent.
Audit Metadata