medusa-plugins
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and development guidelines from Medusa's official site (
docs.medusajs.com). This is a legitimate operation to ensure the agent uses the latest framework standards. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources (documentation fetches and web search results), which constitutes a potential attack surface.
- Ingestion points:
SKILL.md(viaWebFetchof documentation andWebSearchresults). - Boundary markers: Absent.
- Capability inventory:
Bash,Write,Edit,Read,Grep,Glob,WebSearch, andWebFetchare listed in theallowed-toolsofSKILL.md. - Sanitization: Absent.
Audit Metadata