restock

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill ingests data from external sources including Shopify, Square, NetSuite, and user-uploaded CSV files. This represents a potential area to review, as data from these sources could theoretically contain instructions designed to influence the agent's behavior.
  • Ingestion Points: Data enters the agent's context through commerce platform APIs and manual CSV uploads (SKILL.md).
  • Boundary Markers: The instructions do not explicitly define delimiters or specific 'ignore' directives for content within these data sources.
  • Capability Inventory: The skill has the capability to draft emails, generate purchase orders, and stage ledger entries via the WebFetch tool and connected services.
  • Sanitization: There are no specific instructions for sanitizing or filtering input from these external data sources.
  • Human-in-the-Loop Controls: As a positive security measure, the skill explicitly mandates multiple approval gates before committing financial resources or sending external communications, which significantly mitigates the risk of unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:05 PM
Security Audit — agent-trust-hub — restock