shopify-review-triage
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely through reasoning on text inputs provided in the prompt. It has no capabilities for network access, tool usage, or script execution, ensuring a secure execution environment.
- [PROMPT_INJECTION]: The skill processes external review data, creating an indirect prompt injection surface. Analysis: Ingestion points (user-pasted rows in Step 1), Boundary markers (Hard Rule 1 requiring public-only text), Capability inventory (None, reasoning only), Sanitization (Basic keyword and apostrophe normalization). The risk is considered safe as the agent has no tools to abuse if malicious instructions were present in a review.
Audit Metadata