spree-storefront
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents the use of the official
@spree/sdkfor interacting with the commerce backend. All external references point to the vendor's official GitHub repository (github.com/spree) or documentation site (spreecommerce.org). No unauthorized network calls or data exfiltration patterns were detected. The skill correctly distinguishes between publishable keys (safe for client-side) and secret keys (server-side only) and demonstrates standard webhook signature verification to prevent spoofing. No obfuscation, persistence mechanisms, or privilege escalation attempts are present.
Audit Metadata