medusa-testing

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches current testing guidelines and configuration patterns from the official MedusaJS documentation site (docs.medusajs.com) to ensure compatibility with the framework.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes data from external documentation. \n
  • Ingestion points: WebFetch operations targeting docs.medusajs.com as specified in SKILL.md. \n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched content. \n
  • Capability inventory: The agent has access to powerful tools including Bash, Write, Edit, Grep, and Glob. \n
  • Sanitization: There is no explicit validation or sanitization step defined for the content retrieved from the web before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 06:10 AM