sourcing-in-china
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill transmits search queries and product URLs to an external service at
https://mcp.chexb.com/sse. This communication is the intended primary purpose of the skill and is clearly disclosed in the metadata and privacy sections. No access to sensitive files or credentials was detected.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from external product listings and supplier descriptions, creating a surface for indirect prompt injection.\n - Ingestion points: Tools
search_products,search_suppliers, andget_product_detailfetch data from the external MCP proxy.\n - Boundary markers: Absent in the current instruction set.\n
- Capability inventory: No file system modification, command execution, or other dangerous capabilities are defined within the skill's logic.\n
- Sanitization: Not explicitly specified for the inbound external content.
Audit Metadata