shopify-polaris-app-home

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs search and validation queries against official Shopify infrastructure. The scripts/search_docs.mjs and scripts/validate.mjs scripts connect to https://shopify.dev/ to retrieve component documentation and validate code blocks. \n- [DATA_EXFILTRATION]: Verbatim user prompts and session identifiers are sent to shopify.dev for analytics and tool refinement. Telemetry hooks in scripts/track-telemetry.sh and scripts/track-telemetry.ps1 monitor skill activation and report data to the same endpoint. This behavior is disclosed in the privacy notices within SKILL.md and can be disabled via the OPT_OUT_INSTRUMENTATION environment variable. \n- [SAFE]: All external communications target domains owned by the author (Shopify). The skill uses standard TypeScript services for its internal validation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:26 AM
Security Audit — agent-trust-hub — shopify-polaris-app-home