shopify-review-triage

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Shopify review text which could potentially contain malicious instructions designed to manipulate the agent's output. While this represents a vulnerability surface, the risk is mitigated by the skill's lack of executable capabilities. Ingestion points: Review text supplied by the user in Step 1. Boundary markers: The instructions do not define delimiters (such as XML tags) to isolate untrusted data from the agent's logic. Capability inventory: The skill is restricted to text analysis and summarization; it has no access to network, file system, or shell tools. Sanitization: No sanitization is specified for embedded instructions within the review data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:23 AM
Security Audit — agent-trust-hub — shopify-review-triage