spree-extensions
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and guidelines from spreecommerce.org, which is the official website for the Spree Commerce platform. These are legitimate resources for the skill's stated purpose.
- [COMMAND_EXECUTION]: The instructions include the use of shell commands to install the spree_cmd gem and run Rails generators (e.g., bin/rails g spree:extension). These are standard procedures for developing extensions in the Spree ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by fetching and processing external documentation from spreecommerce.org. 1. Ingestion points: Documentation URLs in SKILL.md processed via WebFetch. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the fetching instructions. 3. Capability inventory: The skill has access to Bash, Write, Edit, and Read tools, which could potentially be misused if malicious content were injected into the documentation. 4. Sanitization: There is no mention of sanitizing or validating the content fetched from the external documentation site.
Audit Metadata