etsy-tony-full-launch-pack

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external product data such as SKUs, manufacturing facts, and option matrices. This represents a potential surface for indirect prompt injection if the provided product data contains malicious instructions. However, the risk is negligible as the skill lacks capabilities for file modification, network communication, or code execution.
  • [METADATA_POISONING]: The instructions include a reference to a third-party social media ID (Douyin ID 93440780745, 'Etsy-Tony') for user support and tutorials. While this redirects users off-platform, the skill explicitly mandates that this redirection must not be used to hide steps, request credentials, collect contact information, or report usage data, which aligns with safe practice for developer support.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:46 AM
Security Audit — agent-trust-hub — etsy-tony-full-launch-pack