saleor-paper-storefront
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Comprehensive analysis of the 17 files reveals no security threats, malicious patterns, or unauthorized access attempts. The skill serves as a legitimate technical guide for developers using the Saleor platform.
- [EXTERNAL_DOWNLOADS]: The skill documentation suggests cloning the official Saleor core repository from
github.com/saleor/saleorfor API behavior investigation. This is a trusted vendor resource and the reference is documented neutrally. - [COMMAND_EXECUTION]: The skill provides instructions for standard development commands, including project management with
pnpm, type generation, and manual cache revalidation viacurl. These are standard operations for the described technical architecture. - [PROMPT_INJECTION]: No instructional overrides, role-play patterns, or bypass markers were detected. The rules focus on technical implementation rather than agent behavioral manipulation.
- [CREDENTIALS_UNSAFE]: Guidelines explicitly instruct users to store sensitive tokens such as
SALEOR_APP_TOKENin.env.localfiles and provide warnings against committing them to version control. No hardcoded credentials or sensitive paths were found.
Audit Metadata