ai-ecommerce-expert-tiktok-shop-ecommerce-content

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/imiva_mcp.py uses subprocess.Popen to execute npx. The command structure and package target are hardcoded to the vendor's official library, preventing unauthorized command injection.
  • [REMOTE_CODE_EXECUTION]: The skill dynamically fetches and runs the official @infimind/ecom-content-cli package from the NPM registry via npx. This is a necessary and transparent operation for the skill to access its core content generation capabilities.
  • [DATA_EXFILTRATION]: The skill communicates exclusively with the official vendor domain imiva.ecpro.com. Authentication is managed securely via the MCP_TOKEN environment variable, ensuring that sensitive access tokens are not hardcoded or exposed in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 08:01 AM
Security Audit — agent-trust-hub — ai-ecommerce-expert-tiktok-shop-ecommerce-content