product-opportunity-finder

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation mentions the adjustText Python library, which is a common, well-known package from the Python Package Index (PyPI) used to improve chart readability.
  • [DATA_EXFILTRATION]: Network activity is restricted to a user-defined proxy endpoint (NEXSCOPE_PROXY_BASE) for fetching product data. No patterns suggesting unauthorized data collection or exfiltration of sensitive local information were found.
  • [COMMAND_EXECUTION]: The skill uses local Python scripts to perform calculations and generate charts. These scripts utilize standard libraries and do not involve suspicious system calls, privilege escalation, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from e-commerce product listings (titles and descriptions). While this presents a minor attack surface, the skill formats this data into structured reports, which helps prevent the agent from inadvertently executing instructions embedded within product details.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 04:16 AM
Security Audit — agent-trust-hub — product-opportunity-finder