shopify-liquid
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's scripts (
search_docs.mjsandvalidate.mjs) communicate with Shopify's official domains (shopify.devandshop.dev) to fetch documentation and report validation results. This behavior is clearly documented in the skill's privacy notices and targets a well-known, trusted service. - [REMOTE_CODE_EXECUTION]: Dependencies listed in
package.json(@shopify/theme-check-*) are maintained by the trusted vendor. No unverified or risky remote code execution patterns were detected. - [DATA_EXFILTRATION]: Telemetry scripts (
track-telemetry.shandtrack-telemetry.ps1) are included to report skill usage and session metadata to Shopify. The skill instructions also require the agent to provide the user's prompt in a base64-encoded format to the validation tool for instrumentation. These operations are restricted to the vendor's own infrastructure and are disclosed to the user in the metadata.
Audit Metadata