ecommerce.tiktok-shop-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes store metadata and metrics from the external Kalodata API, which is a potential surface for indirect prompt injection where instructions could be embedded in data fields.\n
  • Ingestion points: External data is fetched and processed by scripts/shop_rank.py and scripts/shop_detail.py.\n
  • Boundary markers: Absent; the skill lacks specific instructions for the agent to ignore or delimit instructions that might be present in the API response.\n
  • Capability inventory: The skill possesses network access (urllib.request) and filesystem write capabilities (open).\n
  • Sanitization: Absent; the skill does not explicitly filter or sanitize the text content of the API responses before presentation.\n- [COMMAND_EXECUTION]: The skill requires the execution of its included Python scripts (scripts/shop_rank.py and scripts/shop_detail.py) to perform its primary function of retrieving shop data. This behavior is documented and follows the intended skill design.\n- [EXTERNAL_DOWNLOADS]: The skill makes network requests to API endpoints and references documentation hosted on the vendor's domain (nexscope.ai). These are identified as legitimate resources owned by the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:46 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-shop-analytics