medusa-api-routes

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate architectural and code instructions for the MedusaJS framework and does not exhibit malicious behavior or intent.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves technical documentation from docs.medusajs.com, which is a well-known and official service for the Medusa commerce framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data from documentation websites. 1. Ingestion points: WebFetch and WebSearch of docs.medusajs.com as described in the 'Before writing code' section of SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Write, Edit, and Bash tools are available. 4. Sanitization: Absent. While this creates an ingestion surface, the risk is negligible given the official and trusted nature of the target content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM