medusa-customers

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and API references from the official MedusaJS documentation site.
  • Evidence: https://docs.medusajs.com/resources/references/customer in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to perform web searches and fetch external content, which is then processed as part of the agent's context.
  • Ingestion points: Multiple Web-search and WebFetch steps in SKILL.md targeting docs.medusajs.com and general search results.
  • Boundary markers: Absent. There are no explicit instructions to the agent to treat fetched documentation or search results as untrusted data or to ignore embedded instructions.
  • Capability inventory: The agent is granted Bash, Write, and Edit tools, which could be leveraged if malicious instructions were ingested via external data.
  • Sanitization: Absent. The instructions do not specify any validation or filtering of the content retrieved from the web before it is used for code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM