ecommerce.tiktok-livestream-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external TikTok livestream leaderboards, creating a surface for potential adversarial content. \n
  • Ingestion points: API responses from the Nexscope proxy are processed in scripts/livestream_rank.py and scripts/livestream_detail.py. \n
  • Boundary markers: The instructions do not provide delimiters or warnings for the agent to ignore instructions that might be embedded in the fetched TikTok data. \n
  • Capability inventory: The skill has capabilities to write files to the local disk and perform network requests via the proxy. \n
  • Sanitization: The skill does not implement specific sanitization or filtering for ingested strings such as livestream titles before they are presented to the agent. \n- [DATA_EXFILTRATION]: The scripts attempt to write session data to the user's home directory as a fallback location. \n
  • Evidence: The _nexscope_root function in both Python scripts includes os.path.expanduser('~') in its search for a writable root directory to store JSON responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:45 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-livestream-analytics