refund-rate-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external data from a Shopify store. Ingestion points: Shopify order and product data retrieved via GraphQL in SKILL.md. Boundary markers: No delimiters or ignore-instructions are specified for the retrieved data. Capability inventory: Terminal output and CSV file creation. Sanitization: No sanitization of product or vendor strings is performed before inclusion in output files or terminal display.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:14 AM