review-aggregator
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external platforms, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: Product and business reviews are fetched from Google Maps, Amazon, Akta, and Xiaohongshu using the
google_maps_bulk_reviews,amazon_bulk_reviews_multi_region,akta_company_product_reviews, andxiaohongshu_app_v2_product_reviewstools as defined in SKILL.md and references/sandbase-api-map.md. - Boundary markers: Absent. The instructions do not require the agent to use delimiters or specific safety instructions when processing ingested review data.
- Capability inventory: The skill is limited to data synthesis and citation; it does not request high-privilege operations like arbitrary shell execution or filesystem writes.
- Sanitization: There is no mention of filtering or sanitizing the external data before analysis.
Audit Metadata