amazon-daily-market-radar

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of monitoring Amazon market data. All external communications are directed to the vendor's official domain (api.zoodata.ai).
  • [COMMAND_EXECUTION]: The skill utilizes a local script (scripts/zoodata.py) to interface with the ZooData API. This script is written using only Python standard libraries (e.g., urllib, json, argparse) and does not download or execute external code.
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of Amazon product reviews. It includes specific defensive measures to prevent Indirect Prompt Injection, such as instructing the agent to wrap review text in triple-quote delimiters and enforcing strict JSON schemas for LLM-generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 12:03 PM
Security Audit — agent-trust-hub — amazon-daily-market-radar