bc-api-rest
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process external content from BigCommerce documentation and general web search results. This represents a vulnerability surface for indirect prompt injection. * Ingestion points: Documentation fetch from docs.bigcommerce.com and web search results via WebFetch and WebSearch tools. * Boundary markers: Not defined in the instructions to protect against or delimit embedded malicious commands. * Capability inventory: Access to file modification (Write, Edit) and shell command execution (Bash). * Sanitization: No explicit content sanitization or validation is implemented.
- [EXTERNAL_DOWNLOADS]: Fetches live developer documentation from BigCommerce's official portal (docs.bigcommerce.com). This behavior is expected for providing up-to-date API references and targets a well-known service.
Audit Metadata