saleor-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch documentation and reference configurations from external web sources (docs.saleor.io and GitHub) to guide the agent's actions. This creates an attack surface where malicious content on those external pages could attempt to influence the agent's behavior.
  • Ingestion points: The 'Before writing code' section in SKILL.md instructs the agent to use WebSearch and WebFetch to retrieve deployment guides and Docker configurations.
  • Boundary markers: The instructions do not define clear delimiters or specific directions to ignore instructions embedded within the fetched external data.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, Edit, and Grep as defined in the frontmatter.
  • Sanitization: There are no explicit mechanisms provided to sanitize or validate the content retrieved from external sources before the agent processes it.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and reference implementation details from the official Saleor GitHub repository (github.com/saleor/saleor-platform) and documentation site (docs.saleor.io).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM