topview-shopee-ops

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and tool routing configuration utilize vendor-owned infrastructure at 'mcp.topview.ai' and follow standard protocols for tool invocation. No evidence of credential theft, unauthorized file access, or persistence mechanisms was found.
  • [PROMPT_INJECTION]: The skill ingests untrusted market data from Shopee via tools like 'queryshopeeitemdata' and 'queryshopeebrandranking' as detailed in 'references/tool_routing.md'. This creates a surface for indirect prompt injection. The skill lacks explicit boundary markers or sanitization instructions for this external content. The agent maintains the capability to perform subsequent tool calls based on the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 07:55 PM
Security Audit — agent-trust-hub — topview-shopee-ops