restock
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill ingests data from external sources including Shopify, Square, NetSuite, and user-uploaded CSV files. This represents a potential area to review, as data from these sources could theoretically contain instructions designed to influence the agent's behavior.
- Ingestion Points: Data enters the agent's context through commerce platform APIs and manual CSV uploads (SKILL.md).
- Boundary Markers: The instructions do not explicitly define delimiters or specific 'ignore' directives for content within these data sources.
- Capability Inventory: The skill has the capability to draft emails, generate purchase orders, and stage ledger entries via the
WebFetchtool and connected services. - Sanitization: There are no specific instructions for sanitizing or filtering input from these external data sources.
- Human-in-the-Loop Controls: As a positive security measure, the skill explicitly mandates multiple approval gates before committing financial resources or sending external communications, which significantly mitigates the risk of unauthorized actions.
Audit Metadata