ecommerce.tiktok-video-rank

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script (scripts/echotik_list_video_rank.py) to perform API requests. The script uses the urllib library for network communication and implements strict JSON parameter parsing to prevent shell injection or unintended behavior.
  • [DATA_EXPOSURE]: The skill documentation explicitly instructs the agent to redact credentials, signed URLs, and cookies from user-facing output. It also specifies that authentication should be handled via environment variables (NEXSCOPE_API_KEY) rather than hardcoded secrets.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with a specific, documented API endpoint (api.nexscope.ai). These operations are consistent with the skill's primary purpose of fetching marketplace research data and do not involve downloading or executing arbitrary remote code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from a research proxy. It defines clear ingestion points and specifies that business data is nested within a platform envelope, reducing the surface for indirect injection. However, like all skills processing external content, it relies on the model's inherent guardrails for final safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:45 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-video-rank