deco-apps-vtex-porting

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process and port code from an external source (the deco-cx/apps repository). This creates an ingestion point for untrusted data. Since the agent has the capability to write files and manage dependencies as part of the porting task, this represents an indirect prompt injection surface. No specific boundary markers or sanitization logic are defined in the instructions for the content of the files being ported.
  • [EXTERNAL_DOWNLOADS]: The documentation references resources and services from well-known technology providers. This includes assets hosted on Supabase and the integration of platforms like PostHog and Cloudflare Workers. It also specifies the use of standard industry packages such as @tanstack/react-query and cookie. These references are standard for the described technical stack and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:53 AM
Security Audit — agent-trust-hub — deco-apps-vtex-porting