hyva-ui-component
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill uses local Bash and PHP scripts to manage its component catalog and parse configuration data. These scripts were reviewed and found to perform only legitimate text processing and file listing tasks within the local environment.
- [COMMAND_EXECUTION]: Employs standard shell commands such as 'cp', 'find', and 'ls' for managing theme files, and 'composer' for installing vendor-provided Magento packages. These actions are appropriate for the skill's purpose and are scoped to the project's frontend and vendor directories.
- [EXTERNAL_DOWNLOADS]: References official Hyvä Themes domains and verified package registries for downloading and installing UI components. These resources represent legitimate vendor infrastructure and do not involve untrusted or risky third-party servers.
Audit Metadata