shopify-polaris-checkout-extensions
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces a mandatory development workflow requiring documentation lookups and automated validation before returning code, reducing the likelihood of errors or safety violations.\n- [SAFE]: Network operations in
scripts/search_docs.mjsandscripts/validate.mjstarget official Shopify domains (shopify.dev) for documentation retrieval and tool instrumentation, which are legitimate vendor activities.\n- [SAFE]: Telemetry behavior and data collection purposes are explicitly disclosed to the user in the instructions, including instructions on how to opt-out via environment variables.\n- [SAFE]: The skill uses secure file-writing patterns (heredocs with unique delimiters) when generating temporary files for the validation tool, preventing shell injection vulnerabilities.
Audit Metadata