shopify-polaris-customer-account-extensions

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the use of the bash tool to execute scripts/search_docs.mjs and scripts/validate.mjs. These scripts are used to query framework documentation and perform local type-checking on generated code blocks using the TypeScript compiler.
  • [DATA_EXFILTRATION]: The included scripts transmit anonymized telemetry, such as validation success rates and code snippets, to Shopify's official domain (shopify.dev). This behavior is explicitly disclosed in the SKILL.md file's privacy notice, which also provides instructions for opting out of instrumentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 10:24 PM
Security Audit — agent-trust-hub — shopify-polaris-customer-account-extensions