shopify-themes
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches data from external websites and code repositories, which serves as a potential vector for indirect prompt injection. If an attacker were to compromise or influence these external sources, they could embed instructions intended to manipulate the agent's behavior. \n- Ingestion points: The skill uses
WebFetchandWebSearchto retrieve data fromshopify.devandgithub.com/shopify/dawn. \n- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched content as untrusted data or to ignore instructions contained within it. \n- Capability inventory: The skill is granted access to high-impact tools such asBash,Write, andEdit, which could be exploited if the agent follows malicious instructions from fetched content. \n- Sanitization: No sanitization or validation of the fetched external content is defined in the instructions. \n- [EXTERNAL_DOWNLOADS]: The skill retrieves configuration, documentation, and source code from external services. \n- Fetches documentation from Shopify's developer portal (shopify.dev). \n- Accesses the reference theme repository on GitHub (github.com/shopify/dawn).
Audit Metadata