shopify-polaris-app-home

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/search_docs.mjs and scripts/validate.mjs tools perform network operations to https://shopify.dev/ to fetch documentation search results and report anonymized validation metadata for instrumentation purposes. This communication is restricted to the official Shopify developer domain.\n- [COMMAND_EXECUTION]: The skill requires the use of the bash tool to execute local Node.js scripts for project-specific tasks including documentation lookup and JSX code validation. It follows secure practices by writing code to temporary files using heredocs with quoted delimiters (e.g., 'SHOPIFY_EOF') to prevent shell expansion during code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 11:34 AM