medusa-plugins

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and development guidelines from Medusa's official site (docs.medusajs.com). This is a legitimate operation to ensure the agent uses the latest framework standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources (documentation fetches and web search results), which constitutes a potential attack surface.
  • Ingestion points: SKILL.md (via WebFetch of documentation and WebSearch results).
  • Boundary markers: Absent.
  • Capability inventory: Bash, Write, Edit, Read, Grep, Glob, WebSearch, and WebFetch are listed in the allowed-tools of SKILL.md.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM