saleor-apps

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to fetch documentation and search results from external websites like docs.saleor.io.
  • Ingestion points: WebFetch and WebSearch tools are used to ingest external data into the agent's context in SKILL.md.
  • Boundary markers: No explicit boundary markers or instructions to disregard potential instructions within the fetched data are present.
  • Capability inventory: The agent possesses Write and Bash tools that could be misused if malicious instructions are contained within the fetched documentation or search results.
  • Sanitization: No sanitization or validation of the external web content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 06:09 AM