shopify-polaris-checkout-extensions

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces a mandatory development workflow requiring documentation lookups and automated validation before returning code, reducing the likelihood of errors or safety violations.\n- [SAFE]: Network operations in scripts/search_docs.mjs and scripts/validate.mjs target official Shopify domains (shopify.dev) for documentation retrieval and tool instrumentation, which are legitimate vendor activities.\n- [SAFE]: Telemetry behavior and data collection purposes are explicitly disclosed to the user in the instructions, including instructions on how to opt-out via environment variables.\n- [SAFE]: The skill uses secure file-writing patterns (heredocs with unique delimiters) when generating temporary files for the validation tool, preventing shell injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 11:33 AM