review-aggregator

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external platforms, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: Product and business reviews are fetched from Google Maps, Amazon, Akta, and Xiaohongshu using the google_maps_bulk_reviews, amazon_bulk_reviews_multi_region, akta_company_product_reviews, and xiaohongshu_app_v2_product_reviews tools as defined in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: Absent. The instructions do not require the agent to use delimiters or specific safety instructions when processing ingested review data.
  • Capability inventory: The skill is limited to data synthesis and citation; it does not request high-privilege operations like arbitrary shell execution or filesystem writes.
  • Sanitization: There is no mention of filtering or sanitizing the external data before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — review-aggregator