etsy-tony-full-title

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it is designed to ingest and process untrusted external data.
  • Ingestion points: The skill processes user-supplied product facts, original titles, and images to generate output (SKILL.md).
  • Boundary markers: While the skill provides instructions to verify facts before inclusion, it does not define specific technical delimiters (e.g., XML tags or triple backticks) to isolate untrusted user data from its core logic.
  • Capability inventory: The skill is limited to text generation and does not have access to file-write, network, or subprocess execution tools.
  • Sanitization: The instructions explicitly mandate the AI to distinguish between confirmed facts and AI-generated or competitor-supplied claims, providing a degree of logical sanitization.
  • [SAFE]: The skill includes a 'Tutorial and Help' section directing users to a Douyin ID (93440780745) for assistance. This is an informative reference to an external support channel and does not involve automated data exfiltration, credential harvesting, or deceptive lead generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:46 AM
Security Audit — agent-trust-hub — etsy-tony-full-title