spree-legacy-api-v2

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves exclusively as an instructional resource for developers working with Spree Commerce. It provides context on the legacy API v2 and outlines migration steps to API v3.
  • [EXTERNAL_DOWNLOADS]: The skill mentions official Spree Commerce packages including '@spree/sdk', '@spree/admin-sdk', and '@spree/storefront-api-v2-sdk'. It also references the official 'spree_legacy_api_v2' GitHub repository. These are recognized as legitimate vendor resources from the author 'spree'.
  • [COMMAND_EXECUTION]: The documentation includes 'curl' command examples for authentication and API interaction. These use placeholders (e.g., 'password=…') and are intended for manual developer use, presenting no risk of unauthorized execution.
  • [DATA_EXPOSURE]: While the skill discusses authentication headers and tokens (e.g., 'Authorization: Bearer', 'X-Spree-Order-Token'), it does so in an architectural context. No real credentials or sensitive keys are hardcoded.
  • [SAFE]: No obfuscation, prompt injection, persistence mechanisms, or dynamic execution patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:11 PM
Security Audit — agent-trust-hub — spree-legacy-api-v2