israeli-marketplace-seller
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary functionality is aligned with its stated purpose of managing e-commerce activities in Israel. It includes helpful contextual information regarding local laws, such as VAT requirements and consumer protection regulations.
- [COMMAND_EXECUTION]: The skill uses browser automation (CDP/Playwright) and Python (via the Bash tool) to perform market analysis and inventory management. These actions are standard for automation tasks on platforms where public APIs are limited or unavailable.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of processing untrusted data:
- Ingestion points: Scrapes product data, competitor information, and customer reviews from Zap, KSP, Facebook, and Instagram.
- Boundary markers: There are no explicit instructions to use boundary markers or delimiters when the agent processes external text.
- Capability inventory: The agent has access to
Bash(python:*)andWebFetchto interact with external sites and local storage. - Sanitization: No sanitization or filtering logic is prescribed for data retrieved from external sources before it is interpreted by the model.
- Assessment: This is a documented surface common to all scraping-based tools and does not represent a malicious instruction in the skill itself.
Audit Metadata