medusa-catalog

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and API references from official MedusaJS domains (docs.medusajs.com). This is a well-known service for e-commerce developers, and the resource fetching is consistent with the skill's legitimate purpose.- [INDIRECT_PROMPT_INJECTION]: The skill uses web search and fetch tools to ingest external documentation. Ingestion points: External content from documentation pages and search results. Boundary markers: None explicitly defined in the prompt instructions to isolate external text. Capability inventory: File system access (Read, Write, Edit), shell execution (Bash), and network operations (WebSearch, WebFetch). Sanitization: Not specified in the skill content. While this creates a surface for indirect prompt injection, the risk is negligible as it targets established documentation and follows standard documentation retrieval workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM