shop-orphan-products

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product and collection data (names, descriptions) which are externally controlled. This presents a potential surface for indirect prompt injection if an attacker can modify shop data. However, the risk is mitigated by the skill's design, which requires a dry-run report and explicit user confirmation before executing any write operations (shop_update_product).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:56 PM
Security Audit — agent-trust-hub — shop-orphan-products