product-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted product data from third-party platforms such as Amazon and Xiaohongshu.\n
  • Ingestion points: External data is retrieved through multiple tools including amazon_bulk_reviews_multi_region and xiaohongshu_app_v2_product_reviews as defined in SKILL.md and references/sandbase-api-map.md.\n
  • Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to disregard instructions found within the scraped content (e.g., product descriptions or user reviews).\n
  • Capability inventory: The skill can invoke additional tools via the sandbase_call_tool interface based on findings from initial research steps.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the external content before it is processed by the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — product-intelligence