shopify-html-data-comments

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Prompt Injection] (SAFE): The instructions are benign and aligned with the skill's purpose of providing coding guidelines. No override or bypass attempts were detected.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file access, or network calls are present. Links point to reputable sources like MDN and Shopify.
  • [Remote Code Execution] (SAFE): There are no package installations or remote script executions. The skill consists entirely of Markdown and Liquid/JavaScript code examples.
  • [Dynamic Execution] (SAFE): No dynamic code generation or unsafe deserialization patterns are used.
  • [Indirect Prompt Injection] (SAFE): The skill does not ingest or process untrusted external data, serving only as a reference for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:43 PM