etsy-tony-full-seller-operations

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external materials provided by the user and local knowledge files, creating a surface for indirect prompt injection.
  • Ingestion points: Processes user-provided operational materials and external markdown files.
  • Boundary markers: Absent; no instructions are provided to ignore embedded instructions in ingested text.
  • Capability inventory: The skill is restricted to read-only decision support with no command execution or network capabilities.
  • Sanitization: Absent; no validation or filtering of input data is defined.
  • [METADATA_POISONING]: The skill instructions include a specific social media account ID (Douyin ID 93440780745) for off-platform support. While it contains guidelines to avoid deceptive promotion, it facilitates off-platform redirection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:47 AM
Security Audit — agent-trust-hub — etsy-tony-full-seller-operations