bagisto-theme-sections

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns were detected. The skill effectively documents security best practices for the Bagisto framework, such as requiring specific admin permissions for storefront previews and using internal request attributes instead of query parameters to prevent unauthorized access to unpublished content.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages user-supplied content (HTML and CSS) through the static_content section type, which represents a potential injection surface.
  • Ingestion points: Untrusted data enters via the html and css fields in static_content section types, stored within the theme_section_translations table.
  • Boundary markers: The skill does not define specific LLM-level boundary markers for this data, although it is stored in a structured database schema.
  • Capability inventory: SectionRepository facilitates database reads/writes; SectionObserver manages the deletion of media directories. No command execution or network exfiltration capabilities are exposed.
  • Sanitization: The skill explicitly mandates the use of sanitizeOptions(), which implements sanitizeHtml (via Purify) and sanitizeCss for all content paths (draft, preview, and publish).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:39 PM