etsy-tony-full-seller-operations
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external materials provided by the user and local knowledge files, creating a surface for indirect prompt injection.
- Ingestion points: Processes user-provided operational materials and external markdown files.
- Boundary markers: Absent; no instructions are provided to ignore embedded instructions in ingested text.
- Capability inventory: The skill is restricted to read-only decision support with no command execution or network capabilities.
- Sanitization: Absent; no validation or filtering of input data is defined.
- [METADATA_POISONING]: The skill instructions include a specific social media account ID (Douyin ID 93440780745) for off-platform support. While it contains guidelines to avoid deceptive promotion, it facilitates off-platform redirection.
Audit Metadata