shopify-hydrogen
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches documentation, data-fetching patterns, and project examples from official Shopify domains (
shopify.dev) and the official Shopify GitHub organization. - [COMMAND_EXECUTION]: Employs standard project initialization commands using the official
@shopify/hydrogenpackage and theshopifyCLI tool. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and process live documentation from external sources to ensure code accuracy.
- Ingestion points:
SKILL.mdinstructions guide the agent to useWebSearchandWebFetchtools onshopify.devandgithub.com/shopifyURLs. - Boundary markers: The skill does not explicitly define delimiters for the fetched content.
- Capability inventory: The skill permits the use of
Write,Edit, andBashtools to implement the fetched patterns. - Sanitization: No specific filtering is applied to the documentation fetched from these trusted sources.
Audit Metadata