shopify-customers
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: The skill retrieves customer profile details, order history, and custom metafields through Shopify Admin and Customer Account GraphQL APIs. It also dynamically fetches live documentation and segmentation syntax using the
WebSearchandWebFetchtools. - Boundary markers: The provided instructions do not include specific delimiters or "ignore embedded instructions" warnings to handle content retrieved from external APIs or websites.
- Capability inventory: The skill's configuration in
SKILL.mdallows access to powerful tools includingBash,Write, andEdit. - Sanitization: There are no explicit instructions for validating or filtering the external data received before the agent processes or acts upon it.
Audit Metadata