shopify-admin-stock-velocity-report

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data from a Shopify store which may contain instructions intended to influence the agent's behavior.
  • Ingestion points: Data enters the context via the productVariants and orders GraphQL query results as defined in SKILL.md.
  • Boundary markers: No delimiters or specific instructions are provided to the agent to treat the fetched store data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill utilizes the shopify-admin tool and has the capability to write the results to a local CSV file.
  • Sanitization: The skill does not include any instructions for sanitizing, escaping, or validating the data retrieved from the Shopify API before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:01 AM