compare-prices
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external marketplace APIs, including seller-authored fields like product titles, descriptions, and reviews. These sources represent an attack surface for indirect prompt injection, where a malicious seller could attempt to influence the agent's behavior. The skill documentation explicitly acknowledges this risk in the 'Trust boundary' section, advising that such content should be treated as untrusted.
Audit Metadata