aliexpress-product-data
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill communicates exclusively with the vendor's official API endpoint (api.scavio.dev) to perform its core functions.
- [SAFE]: Sensitive credentials (API keys) are handled using environment variables (SCAVIO_API_KEY), which is the industry standard for secure configuration.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content such as product descriptions and customer reviews from AliExpress. However, the risk is mitigated as the skill does not possess high-privilege capabilities (like arbitrary command execution or file system writes) that could be exploited via malicious data injection.
- [SAFE]: No instances of obfuscation, remote code execution, persistence mechanisms, or unauthorized privilege escalation were detected.
Audit Metadata