shopify-admin-stock-velocity-report
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external data from a Shopify store which may contain instructions intended to influence the agent's behavior.
- Ingestion points: Data enters the context via the productVariants and orders GraphQL query results as defined in SKILL.md.
- Boundary markers: No delimiters or specific instructions are provided to the agent to treat the fetched store data as untrusted or to ignore embedded instructions.
- Capability inventory: The skill utilizes the shopify-admin tool and has the capability to write the results to a local CSV file.
- Sanitization: The skill does not include any instructions for sanitizing, escaping, or validating the data retrieved from the Shopify API before processing it.
Audit Metadata