shopify-partner-marketing

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's runbook (references/exam-prep.md §4) explicitly instructs the agent to open and read the public Shopify Academy assessment page (shopifyacademy.com) in Chrome as part of the exam workflow, and other instructions (e.g., using BuiltWith/Wappalyzer/Shopify public listings for ABM list building) require ingesting public third‑party web content that will be read and acted on, so the agent is exposed to untrusted third‑party content that can influence its decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 01:40 PM
Issues
1
Security Audit — snyk — shopify-partner-marketing