sales-spree
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill implements a persistent learning mechanism where it appends new discoveries to
references/learnings.md. * Ingestion points: User requests regarding Spree Commerce platform features or troubleshooting processed inSKILL.md. * Boundary markers: None identified. The agent is instructed to append findings directly to the file without explicit delimiters. * Capability inventory: The skill specifies reading fromreferences/learnings.mdduring initialization and appending to it in the final step of the instructions. * Sanitization: No explicit sanitization or validation of the content being appended is required, creating a surface for indirect prompt injection if malicious data is perceived as a valid 'learning'. - [EXTERNAL_DOWNLOADS]: The skill provides instructions and examples for downloading external tools and documentation. * Mentions installing agent skills from the
spree/agent-skillsGitHub repository vianpx. * References an external MCP server for documentation athttps://spreecommerce.org/docs/mcp. * Includes commands to install related vendor tools fromsales-skills/sales.
Audit Metadata