product-opportunity-finder
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation mentions the
adjustTextPython library, which is a common, well-known package from the Python Package Index (PyPI) used to improve chart readability. - [DATA_EXFILTRATION]: Network activity is restricted to a user-defined proxy endpoint (
NEXSCOPE_PROXY_BASE) for fetching product data. No patterns suggesting unauthorized data collection or exfiltration of sensitive local information were found. - [COMMAND_EXECUTION]: The skill uses local Python scripts to perform calculations and generate charts. These scripts utilize standard libraries and do not involve suspicious system calls, privilege escalation, or persistence mechanisms.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from e-commerce product listings (titles and descriptions). While this presents a minor attack surface, the skill formats this data into structured reports, which helps prevent the agent from inadvertently executing instructions embedded within product details.
Audit Metadata