bc-customers
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch external data from the BigCommerce developer portal and interact with customer records, creating a surface for potential indirect injection if processed data contains malicious instructions.\n
- Ingestion points: Data ingested from
WebFetchandWebSearchtools, and results from BigCommerce REST/GraphQL API calls.\n - Boundary markers: None explicitly defined in the instructions for separating untrusted data from the prompt.\n
- Capability inventory: The skill has access to
Bash,Write,Edit, andWebFetchtools which could be used to act on data.\n - Sanitization: No specific sanitization or validation logic is provided within the skill instructions, as it is primarily a documentation reference.
Audit Metadata