shopify-pos-ui

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and search results from Shopify's official developer domain (shopify.dev). This is standard functionality for providing up-to-date API information.- [COMMAND_EXECUTION]: The skill executes provided helper scripts (search_docs.mjs and validate.mjs) to perform search and code validation tasks. These scripts are bundled within the skill and use the local Node.js environment.- [DATA_EXFILTRATION]: Anonymized telemetry regarding tool usage and code validation results is sent to Shopify's servers for service improvement. This behavior is documented and includes an opt-out option via environment variables.- [PROMPT_INJECTION]: Instructions are focused on legitimate developer workflows and do not contain patterns attempting to bypass model safety guidelines or extract system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 12:22 AM
Security Audit — agent-trust-hub — shopify-pos-ui