ecommerce.tiktok-shop-analytics
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes store metadata and metrics from the external Kalodata API, which is a potential surface for indirect prompt injection where instructions could be embedded in data fields.\n
- Ingestion points: External data is fetched and processed by
scripts/shop_rank.pyandscripts/shop_detail.py.\n - Boundary markers: Absent; the skill lacks specific instructions for the agent to ignore or delimit instructions that might be present in the API response.\n
- Capability inventory: The skill possesses network access (
urllib.request) and filesystem write capabilities (open).\n - Sanitization: Absent; the skill does not explicitly filter or sanitize the text content of the API responses before presentation.\n- [COMMAND_EXECUTION]: The skill requires the execution of its included Python scripts (
scripts/shop_rank.pyandscripts/shop_detail.py) to perform its primary function of retrieving shop data. This behavior is documented and follows the intended skill design.\n- [EXTERNAL_DOWNLOADS]: The skill makes network requests to API endpoints and references documentation hosted on the vendor's domain (nexscope.ai). These are identified as legitimate resources owned by the skill's author.
Audit Metadata