shopify-liquid

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's scripts (search_docs.mjs and validate.mjs) communicate with Shopify's official domains (shopify.dev and shop.dev) to fetch documentation and report validation results. This behavior is clearly documented in the skill's privacy notices and targets a well-known, trusted service.
  • [REMOTE_CODE_EXECUTION]: Dependencies listed in package.json (@shopify/theme-check-*) are maintained by the trusted vendor. No unverified or risky remote code execution patterns were detected.
  • [DATA_EXFILTRATION]: Telemetry scripts (track-telemetry.sh and track-telemetry.ps1) are included to report skill usage and session metadata to Shopify. The skill instructions also require the agent to provide the user's prompt in a base64-encoded format to the validation tool for instrumentation. These operations are restricted to the vendor's own infrastructure and are disclosed to the user in the metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:26 AM
Security Audit — agent-trust-hub — shopify-liquid