bc-channels
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential surface for indirect prompt injection as it is designed to ingest external data from documentation websites.
- Ingestion points: The skill instructs the agent to use
WebFetchto retrieve content fromdeveloper.bigcommerce.comwithinSKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands in the fetched documentation are provided.
- Capability inventory: The agent is permitted to use
Bash,Write, andEdittools as defined in the skill configuration. - Sanitization: The skill does not define methods for sanitizing or validating the content retrieved from external documentation sources.
Audit Metadata