compare-prices

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external marketplace APIs, including seller-authored fields like product titles, descriptions, and reviews. These sources represent an attack surface for indirect prompt injection, where a malicious seller could attempt to influence the agent's behavior. The skill documentation explicitly acknowledges this risk in the 'Trust boundary' section, advising that such content should be treated as untrusted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 PM
Security Audit — agent-trust-hub — compare-prices