product-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted product data from third-party platforms such as Amazon and Xiaohongshu.\n
- Ingestion points: External data is retrieved through multiple tools including
amazon_bulk_reviews_multi_regionandxiaohongshu_app_v2_product_reviewsas defined inSKILL.mdandreferences/sandbase-api-map.md.\n - Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to disregard instructions found within the scraped content (e.g., product descriptions or user reviews).\n
- Capability inventory: The skill can invoke additional tools via the
sandbase_call_toolinterface based on findings from initial research steps.\n - Sanitization: There is no evidence of sanitization, filtering, or validation of the external content before it is processed by the agent context.
Audit Metadata