nuvemshop-sdk
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a technical reference guide for the Nuvemshop developer ecosystem. It provides accurate guidance on API usage, OAuth 2.0 implementation, and UI development using the Nimbus Design System.
- [EXTERNAL_DOWNLOADS]: The skill references several official platform domains, including dev.nuvemshop.com.br, tiendanube.com, nimbus.nuvemshop.com.br, and tiendanube.github.io. It also lists official NPM packages such as @nimbus-ds and @tiendanube/nube-sdk-types. These are all well-known, trusted resources associated with the Nuvemshop/Tiendanube organization.
- [CREDENTIALS_UNSAFE]: Technical discussions regarding access_token, client_id, and client_secret are provided within the context of explaining the OAuth flow and debugging embedded apps. No hardcoded secrets or credentials are present in the skill files.
- [COMMAND_EXECUTION]: The documentation mentions standard development tools and workflows, such as using Docker build arguments or grepping bundle files for debugging purposes. These are educational instructions for the developer and are not automated by the skill itself.
- [PROMPT_INJECTION]: The skill includes instructional constraints ('Hard Pitfalls' and 'Core Rules') designed to ensure the AI provides accurate and safe technical advice. No patterns attempting to bypass safety filters or override system instructions were detected.
Audit Metadata