faststore-storefront

Fail

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script scripts/cms-sync.sh and explicit instructions in references/cms-schema-and-section-registration.md that utilize the expect utility to automate interaction with the vtex CLI. This allows the agent to execute shell commands and provide automated responses to prompts on the user's behalf.
  • [EXTERNAL_DOWNLOADS]: Code examples in references/extending-graphql-with-custom-resolvers.md demonstrate making network requests to external endpoints, including http://viacep.com.br, https://playground.vtexcommercestable.com.br, and https://your-api-endpoint.com. While these appear to be placeholder examples, the endpoint https://your-api-endpoint.com/api/contact was flagged as malicious by automated security scans.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 14, 2026, 01:09 PM