gumroad
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from the Gumroad API, including sales records, buyer details, and product descriptions, while also possessing capabilities to send emails, write files, and modify account settings. This creates an attack surface where instructions embedded in store data could potentially influence the agent's behavior.
- Ingestion points: Data enters the agent context through various CLI commands such as
sales list,sales buyers, andproducts viewin SKILL.md. - Boundary markers: While the instructions recommend using
--jsonand--jqfor structured data access, which provides some isolation, there are no explicit instructions for the agent to treat external data as untrusted or to use specific delimiters when interpolating this data into prompts. - Capability inventory: The skill has extensive write and execution capabilities, including file system writes (
pages pull,products content get), network-altering actions (emails send,webhooks create), and administrative account modifications (admin users suspend). - Sanitization: The skill mentions a backend sanitizer specifically for custom HTML page uploads (
products page preview), but does not define sanitization procedures for other types of processed data like customer-supplied names or email bodies.
Audit Metadata