spree-checkout

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive developer guide for the Spree e-commerce checkout logic, providing Ruby code examples for state machine customization and service overrides.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected in the instructions.
  • [DATA_EXFILTRATION]: The skill does not contain any network requests or file system operations that could lead to data exfiltration. References to the X-Spree-Token header are instructional for API usage and do not expose actual credentials.
  • [EXTERNAL_DOWNLOADS]: No remote scripts or unauthorized packages are downloaded or executed. References to documentation inside node_modules are standard for local project introspection.
  • [COMMAND_EXECUTION]: The skill contains code snippets for instructional purposes but does not involve the direct execution of arbitrary shell commands or system-level modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:11 PM
Security Audit — agent-trust-hub — spree-checkout