saleor-apps
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to fetch documentation and search results from external websites like docs.saleor.io.
- Ingestion points: WebFetch and WebSearch tools are used to ingest external data into the agent's context in SKILL.md.
- Boundary markers: No explicit boundary markers or instructions to disregard potential instructions within the fetched data are present.
- Capability inventory: The agent possesses Write and Bash tools that could be misused if malicious instructions are contained within the fetched documentation or search results.
- Sanitization: No sanitization or validation of the external web content is performed before processing.
Audit Metadata