ecommerce-email-marketing-builder
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is to provide structured instructions for an AI to generate marketing copy, email flows, and strategy recommendations. No malicious patterns such as credential harvesting or privilege escalation were identified.
- [EXTERNAL_DOWNLOADS]: The skill includes installation instructions using the 'npx' command for a package associated with the vendor ('nexscope-ai/eCommerce-Skills'). These resources originate from the skill author and are part of the standard installation workflow.
- [PROMPT_INJECTION]: The skill involves processing user-supplied information, including business details and competitor URLs (documented in Step 1 and Step 2, Q7). While this introduces a surface for indirect prompt injection, the skill lacks boundary markers or sanitization for this external data. However, the risk is negligible as the skill's capabilities are limited to generating markdown text and do not include system-level execution or data exfiltration.
Audit Metadata