bagisto-theme-sections
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns were detected. The skill effectively documents security best practices for the Bagisto framework, such as requiring specific admin permissions for storefront previews and using internal request attributes instead of query parameters to prevent unauthorized access to unpublished content.
- [INDIRECT_PROMPT_INJECTION]: The skill manages user-supplied content (HTML and CSS) through the
static_contentsection type, which represents a potential injection surface. - Ingestion points: Untrusted data enters via the
htmlandcssfields instatic_contentsection types, stored within thetheme_section_translationstable. - Boundary markers: The skill does not define specific LLM-level boundary markers for this data, although it is stored in a structured database schema.
- Capability inventory:
SectionRepositoryfacilitates database reads/writes;SectionObservermanages the deletion of media directories. No command execution or network exfiltration capabilities are exposed. - Sanitization: The skill explicitly mandates the use of
sanitizeOptions(), which implementssanitizeHtml(via Purify) andsanitizeCssfor all content paths (draft, preview, and publish).
Audit Metadata