spree-typescript-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch live documentation from external sources to inform its actions, which introduces a potential attack surface if those sources are compromised.
  • Ingestion points: External data is fetched from spreecommerce.org and github.com/spree/sdk (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat fetched content as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill possesses WebFetch for data ingestion and Bash, Write, and Edit tools that could be influenced by malicious content in the documentation.
  • Sanitization: No sanitization or validation steps are defined for the content retrieved from external URLs.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @spree/sdk package from the npm registry. This is a standard, well-known package for Spree Commerce development and is considered a safe dependency reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM