medusa-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions frequently require the agent to use
WebSearchandWebFetchto ingest documentation fromdocs.medusajs.com. This external data ingestion combined with the agent's ability to write code and execute shell commands creates a surface for indirect prompt injection. - Ingestion points: Multiple instructions in
SKILL.mdto fetch live documentation and search for testing patterns ondocs.medusajs.com. - Boundary markers: The skill does not provide clear delimiters or instructions to the agent to ignore potentially malicious directions embedded in the fetched documentation.
- Capability inventory: The skill is granted
Write,Edit, andBashtools, which could be leveraged if the agent follows malicious instructions from a compromised external source. - Sanitization: There is no evidence of sanitization or validation mechanisms for the content fetched from the web.
- [EXTERNAL_DOWNLOADS]: The skill makes several requests to fetch documentation from
docs.medusajs.comand mentions standard testing dependencies. - Evidence: References to fetching resources from
https://docs.medusajs.com/resources/medusa-testingand searching the official docs for integration test utilities and setup.
Audit Metadata