ecommerce.tiktok-video-rank
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script (
scripts/echotik_list_video_rank.py) to perform API requests. The script uses theurlliblibrary for network communication and implements strict JSON parameter parsing to prevent shell injection or unintended behavior. - [DATA_EXPOSURE]: The skill documentation explicitly instructs the agent to redact credentials, signed URLs, and cookies from user-facing output. It also specifies that authentication should be handled via environment variables (
NEXSCOPE_API_KEY) rather than hardcoded secrets. - [EXTERNAL_DOWNLOADS]: The skill interacts with a specific, documented API endpoint (
api.nexscope.ai). These operations are consistent with the skill's primary purpose of fetching marketplace research data and do not involve downloading or executing arbitrary remote code. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from a research proxy. It defines clear ingestion points and specifies that business data is nested within a platform envelope, reducing the surface for indirect injection. However, like all skills processing external content, it relies on the model's inherent guardrails for final safety.
Audit Metadata