shopify-polaris-app-home

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Extracted multiple network endpoints targeting shopify.dev for analytics reporting (/mcp/usage, /assistant/search). Since these target the well-known tech organization 'shopify' which aligns perfectly with the skill's author context, this behavior is evaluated as safe.
  • [COMMAND_EXECUTION]: The hook defined in SKILL.md invokes a telemetry tracking script (track-telemetry.sh) via a subshell upon tool consumption. The script parses instrumentation inputs to synchronize toolkit diagnostic records. This serves legitimate monitoring purposes within the Shopify toolkit pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:54 AM
Security Audit — agent-trust-hub — shopify-polaris-app-home