ecommerce.tiktok-product-analytics
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides two Python scripts,
scripts/product_rank.pyandscripts/product_detail.py, which are intended to be executed by the agent to perform network operations and manage local data files.\n- [INDIRECT_PROMPT_INJECTION]: The skill fetches product data (such as product names and shop identities) from an external TikTok-linked API and stores it in the local workspace. This creates a vulnerability surface where malicious instructions could be embedded in product metadata to target the agent during data processing.\n - Ingestion points: Data retrieved from the Kalodata API in
scripts/product_detail.pyandscripts/product_rank.py.\n - Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to treat the saved JSON content as untrusted data.\n
- Capability inventory: The skill scripts have the ability to write files to the session data directory in the local filesystem.\n
- Sanitization: While the scripts use standard JSON serialization for data storage, they do not perform sanitization of the natural language strings contained within the product metadata. Large responses (>8 KB) are summarized before printing to stdout, which provides a layer of defense against immediate context poisoning.
Audit Metadata