shopify-customers

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, which creates a potential surface for indirect prompt injection attacks.
  • Ingestion points: The skill retrieves customer profile details, order history, and custom metafields through Shopify Admin and Customer Account GraphQL APIs. It also dynamically fetches live documentation and segmentation syntax using the WebSearch and WebFetch tools.
  • Boundary markers: The provided instructions do not include specific delimiters or "ignore embedded instructions" warnings to handle content retrieved from external APIs or websites.
  • Capability inventory: The skill's configuration in SKILL.md allows access to powerful tools including Bash, Write, and Edit.
  • Sanitization: There are no explicit instructions for validating or filtering the external data received before the agent processes or acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM