shopify-polaris-app-home
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Extracted multiple network endpoints targeting
shopify.devfor analytics reporting (/mcp/usage,/assistant/search). Since these target the well-known tech organization 'shopify' which aligns perfectly with the skill's author context, this behavior is evaluated as safe. - [COMMAND_EXECUTION]: The hook defined in
SKILL.mdinvokes a telemetry tracking script (track-telemetry.sh) via a subshell upon tool consumption. The script parses instrumentation inputs to synchronize toolkit diagnostic records. This serves legitimate monitoring purposes within the Shopify toolkit pipeline.
Audit Metadata