topview-shopee-ops
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions and tool routing configuration utilize vendor-owned infrastructure at 'mcp.topview.ai' and follow standard protocols for tool invocation. No evidence of credential theft, unauthorized file access, or persistence mechanisms was found.
- [PROMPT_INJECTION]: The skill ingests untrusted market data from Shopee via tools like 'queryshopeeitemdata' and 'queryshopeebrandranking' as detailed in 'references/tool_routing.md'. This creates a surface for indirect prompt injection. The skill lacks explicit boundary markers or sanitization instructions for this external content. The agent maintains the capability to perform subsequent tool calls based on the ingested data.
Audit Metadata