medusa-customers
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches documentation and API references from the official MedusaJS documentation site.
- Evidence:
https://docs.medusajs.com/resources/references/customerinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to perform web searches and fetch external content, which is then processed as part of the agent's context.
- Ingestion points: Multiple
Web-searchandWebFetchsteps inSKILL.mdtargetingdocs.medusajs.comand general search results. - Boundary markers: Absent. There are no explicit instructions to the agent to treat fetched documentation or search results as untrusted data or to ignore embedded instructions.
- Capability inventory: The agent is granted
Bash,Write, andEdittools, which could be leveraged if malicious instructions were ingested via external data. - Sanitization: Absent. The instructions do not specify any validation or filtering of the content retrieved from the web before it is used for code generation.
Audit Metadata