skills/simota/agent-skills/haul/Gen Agent Trust Hub

haul

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust verification workflow that prioritizes deterministic matching (SKU, JAN, ASIN) and perceptual similarity scoring, which mitigates the risk of processing malicious or incorrect product data.\n- [SAFE]: Security hardening is integrated into the core instructions, explicitly forbidding the hardcoding of API keys and requiring the redaction of secrets from all logs, reports, and persisted artifacts.\n- [SAFE]: External dependencies and network requests are limited to well-known services such as Amazon, Rakuten, Shopify, eBay, Walmart, and Google/Bing search APIs, which are documented as safe resources.\n- [SAFE]: The skill enforces rigorous data provenance, requiring source URLs, license classifications, and file hashes for every deliverable, ensuring full auditability of collected content.\n- [PROMPT_INJECTION]: The skill processes untrusted input (product lists) and third-party API responses, establishing an indirect prompt injection surface. However, the instructions emphasize structured validation and identifier matching rather than following natural language instructions found within the data, which significantly lowers the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 10:14 AM