israeli-marketplace-seller

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary functionality is aligned with its stated purpose of managing e-commerce activities in Israel. It includes helpful contextual information regarding local laws, such as VAT requirements and consumer protection regulations.
  • [COMMAND_EXECUTION]: The skill uses browser automation (CDP/Playwright) and Python (via the Bash tool) to perform market analysis and inventory management. These actions are standard for automation tasks on platforms where public APIs are limited or unavailable.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of processing untrusted data:
  • Ingestion points: Scrapes product data, competitor information, and customer reviews from Zap, KSP, Facebook, and Instagram.
  • Boundary markers: There are no explicit instructions to use boundary markers or delimiters when the agent processes external text.
  • Capability inventory: The agent has access to Bash(python:*) and WebFetch to interact with external sites and local storage.
  • Sanitization: No sanitization or filtering logic is prescribed for data retrieved from external sources before it is interpreted by the model.
  • Assessment: This is a documented surface common to all scraping-based tools and does not represent a malicious instruction in the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:15 PM
Security Audit — agent-trust-hub — israeli-marketplace-seller