salla-shipping-app
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured guide for developing shipping applications within the Salla Partners ecosystem, utilizing legitimate platform tools such as salla_apps, salla_shipping, and salla_functions for deployment and configuration.
- [SAFE]: External resources and URLs referenced in the documentation belong to trusted or well-known services, specifically official Salla documentation (docs.salla.dev), the Salla Admin API (api.salla.dev), and established developer tools like Postman.
- [SAFE]: The skill prioritizes security by instructing developers to use minimum necessary OAuth scopes, store merchant credentials using encryption, and avoid logging sensitive information such as customer names, phone numbers, or authentication tokens.
- [PROMPT_INJECTION]: The skill facilitates the processing of external data (shipment and order details) within App Functions, creating an indirect injection surface. 1. Ingestion points: context.payload.data (SKILL.md, shipment-cycle.md). 2. Boundary markers: Not specified in code templates. 3. Capability inventory: Code deployment and execution via salla_functions. 4. Sanitization: Explicit documentation encourages secure PII handling.
Audit Metadata