shoplazza-customers
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides mappings for an agent to execute commands via the
shoplazzaCLI tool. These commands are scoped to customer management (create, search, count, update) and shipping address management. All operations align with the skill's stated purpose. - [DATA_EXPOSURE]: The skill handles Personally Identifiable Information (PII) such as email addresses, phone numbers, and physical addresses. This data handling is intrinsic to the skill's functionality as a customer management tool. The instructions explicitly warn the agent to never fabricate contact identifiers and to ask the user if information is missing.
- [PROMPT_INJECTION]: No malicious override or bypass instructions were found. The skill references a safety protocol in its common configuration (
shoplazza-common/SKILL.md) and instructs the agent to useAskUserQuestionfor ambiguous inputs rather than making assumptions.
Audit Metadata