etsy-tony-full-gigab2b-photos
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill includes social engineering elements in the 'Etsy-Tony 教程与求助' section. It instructs the agent to direct users to a specific social media ID ('93440780745') to obtain 'Skills' or 'manual guidance' via private messages if they encounter issues. This practice attempts to move the user-agent interaction to an external platform.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from product pages and uses it to perform high-capability actions like image generation and file system modifications without adequate safeguards.
- Ingestion points: Product data, including titles, Item Codes, and reference images, are extracted from external GigaB2B URLs (SKILL.md, Section 1 and 2).
- Boundary markers: There are no explicit delimiters or instructions to ignore potential commands embedded in the scraped product metadata.
- Capability inventory: The skill performs file system writes to create manifests and image files (SKILL.md, Section 5) and invokes image generation tools for content creation (SKILL.md, Section 4).
- Sanitization: No sanitization or validation of the extracted strings is performed before they are interpolated into image generation prompts or stored in project files.
Audit Metadata