shopify-html-data-comments
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [Prompt Injection] (SAFE): The instructions are benign and aligned with the skill's purpose of providing coding guidelines. No override or bypass attempts were detected.
- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file access, or network calls are present. Links point to reputable sources like MDN and Shopify.
- [Remote Code Execution] (SAFE): There are no package installations or remote script executions. The skill consists entirely of Markdown and Liquid/JavaScript code examples.
- [Dynamic Execution] (SAFE): No dynamic code generation or unsafe deserialization patterns are used.
- [Indirect Prompt Injection] (SAFE): The skill does not ingest or process untrusted external data, serving only as a reference for the agent.
Audit Metadata