shopify-theme-performance

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on Shopify theme templates and configuration files as input data, creating an attack surface where malicious content within these files could influence agent actions.
  • Ingestion points: The agent is instructed to read and edit .liquid, .json, and .css files in the theme directory.
  • Boundary markers: The instructions lack specific guidance for the agent to distinguish between its operational instructions and the content of the files being edited.
  • Capability inventory: The skill uses tools for reading, writing, and editing files, along with shell command execution capabilities (npx).
  • Sanitization: No procedures are provided to sanitize or validate the content extracted from theme files before the agent processes or interpolates it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:47 AM
Security Audit — agent-trust-hub — shopify-theme-performance