post-purchase-extension

Pass

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical reference for the @shopify/post-purchase-ui-extensions-react SDK. It includes component catalogs, API contracts, and usage patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references official Shopify documentation on the shopify.dev domain. These links provide canonical information for developers and are from a well-known, trusted service.
  • [COMMAND_EXECUTION]: Instructions include running npx tsc --noEmit for code validation. This is a standard development workflow for TypeScript projects and does not present a security risk in this context.
  • [SAFE]: The skill explicitly advises against client-side signing of changesets and recommends using a backend with an API secret, demonstrating adherence to security best practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
May 3, 2026, 01:55 AM