sourcing-in-china

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits search queries and product URLs to an external service at https://mcp.chexb.com/sse. This communication is the intended primary purpose of the skill and is clearly disclosed in the metadata and privacy sections. No access to sensitive files or credentials was detected.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from external product listings and supplier descriptions, creating a surface for indirect prompt injection.\n
  • Ingestion points: Tools search_products, search_suppliers, and get_product_detail fetch data from the external MCP proxy.\n
  • Boundary markers: Absent in the current instruction set.\n
  • Capability inventory: No file system modification, command execution, or other dangerous capabilities are defined within the skill's logic.\n
  • Sanitization: Not explicitly specified for the inbound external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 12:11 AM
Security Audit — agent-trust-hub — sourcing-in-china