aliexpress-product-data

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill communicates exclusively with the vendor's official API endpoint (api.scavio.dev) to perform its core functions.
  • [SAFE]: Sensitive credentials (API keys) are handled using environment variables (SCAVIO_API_KEY), which is the industry standard for secure configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content such as product descriptions and customer reviews from AliExpress. However, the risk is mitigated as the skill does not possess high-privilege capabilities (like arbitrary command execution or file system writes) that could be exploited via malicious data injection.
  • [SAFE]: No instances of obfuscation, remote code execution, persistence mechanisms, or unauthorized privilege escalation were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:23 PM
Security Audit — agent-trust-hub — aliexpress-product-data