ecommerce.tiktok-shop-product-detail

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product details from TikTok Shop, which is an external, third-party marketplace. This presents a surface for indirect prompt injection, where malicious content in product titles or descriptions could attempt to influence the agent's instructions. The skill includes mitigation instructions to summarize only facts and preserve original values.
  • Ingestion points: The scripts/tiktok_shop_product_detail.py script retrieves external product data from the TikTok Shop marketplace via a proxy.
  • Boundary markers: SKILL.md contains instructions for the agent to "Summarize only returned facts" and "Preserve source currencies... do not invent conversions."
  • Capability inventory: The skill calls a Python script that has network access and the ability to write JSON data to several local filesystem locations for caching.
  • Sanitization: There is no explicit sanitization, filtering, or escaping of the external product data before it is presented to the agent.
  • [DYNAMIC_EXECUTION]: The script scripts/tiktok_shop_product_detail.py dynamically modifies the Python module search path (sys.path) at runtime to include a relative directory (../../_shared). This is a form of dynamic path manipulation used for loading shared resources.
  • [COMMAND_EXECUTION]: The skill relies on a Python script to perform marketplace queries. This script takes JSON parameters from the command line and performs network operations and local file system writes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:45 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-shop-product-detail