magento2-warden

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the execution of the warden CLI tool to perform environment management, database operations, and Magento-specific tasks.- [DATA_EXPOSURE_AND_EXFILTRATION]: Includes predefined SQL queries to retrieve sensitive information from the Magento database, including administrative user details, customer counts, and order information.- [PRIVILEGE_ESCALATION]: Provides a command to access the container shell with root privileges (warden shell --user root), which is common for development environments.- [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-provided data into SQL queries and shell commands. Ingestion points: User-provided values for placeholders like {search_term}, {sku}, and {Vendor} in SKILL.md. Boundary markers: Absent. Capability inventory: Executes shell commands via warden and performs database mutations via warden db connect. Sanitization: Absent, but the skill includes a workflow rule requiring the agent to seek user confirmation before executing any destructive operations (e.g., UPDATE, DELETE).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 01:13 AM