shopify-pos-ui

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the bash tool to run Shopify CLI commands such as shopify app init and shopify app generate extension for scaffolding projects. It also executes local utility scripts scripts/search_docs.mjs and scripts/validate.mjs as part of the standard development workflow.\n- [EXTERNAL_DOWNLOADS]: The skill's package.json defines standard dependencies like typescript, preact, and @shopify/ui-extensions. These are well-known packages sourced from official package registries.\n- [DATA_EXFILTRATION]: Both search and validation scripts contain instrumentation logic that sends telemetry (including documentation queries and the code being validated) to shopify.dev. This is disclosed in a privacy notice in the skill instructions and targets the official infrastructure of the trusted author (Shopify).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 11:33 AM