ecommerce-product-manager
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The instructions focus exclusively on professional e-commerce management tasks. No patterns indicative of jailbreaking, system prompt extraction, or safety filter bypass were detected.
- [DATA_EXFILTRATION]: No unauthorized data access or external network transmission patterns were identified. The skill does not reference sensitive local files or use tools for network exfiltration.
- [REMOTE_CODE_EXECUTION]: There is no evidence of scripts or commands that download and execute remote content. The skill consists entirely of markdown-based documentation and instructions.
- [COMMAND_EXECUTION]: The troubleshooting guides include standard administrative shell commands for e-commerce platforms (e.g., Magento image resizing). These are provided for instructional purposes and are not executed by the agent automatically.
- [OBFUSCATION]: Analysis of all files, including references and examples, confirms the absence of Base64 encoding, hex escapes, or hidden Unicode characters.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies ingestion points for external data such as user feedback and analytics reports. However, it lacks the necessary capabilities (such as automated script execution or tool use) to be exploited via these inputs.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or credentials were found. The skill does not instruct users to handle secrets in an insecure manner.
- [NO_CODE]: The skill package is composed entirely of markdown documentation and contains no executable code files, reducing its attack surface.
Audit Metadata