bankr-shopify
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Shopify customer profiles which can be used to influence the agent's behavior through the Bankr bridge.\n
- Ingestion points: Data enters the agent context from Shopify customer metafields, specifically the handle resolution logic in SKILL.md.\n
- Boundary markers: The instructions for the Bankr bridge lack clear boundary markers or instructions to the agent to disregard commands embedded within the retrieved metafield values.\n
- Capability inventory: The skill uses curl in SKILL.md to interact with the Bankr API, enabling on-chain transactions and job submissions.\n
- Sanitization: The customer-provided handle is interpolated into a natural language prompt string without prior validation or sanitization to ensure it only contains a valid identity handle.
Audit Metadata