saleor-catalog
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches API schema details and developer guidelines from Saleor's official documentation at docs.saleor.io.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites and web search results, creating a theoretical attack surface for indirect prompt injection if those sources were to contain malicious instructions.
- Ingestion points: External documentation URLs and search queries defined in the 'Before writing code' section of SKILL.md.
- Boundary markers: Absent; there are no specific instructions provided to the agent to ignore or delimit instructions found within the fetched documentation.
- Capability inventory: The skill allows access to file system operations (Read, Write, Edit), network tools (WebSearch, WebFetch), and shell access (Bash) via the allowed-tools configuration.
- Sanitization: Absent; the skill does not define validation or filtering steps for the content retrieved from external sources.
Audit Metadata