spree-typescript-sdk

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation for the @spree/sdk and @spree/admin-sdk packages, which are legitimate resources from the author 'spree'.
  • [SAFE]: Includes an example publishable key (pk_CzEKBTWFiuNLgz4wciLsS59n) for demonstration; as a publishable key, it is intended for client-side use and does not represent a sensitive credential exposure.
  • [SAFE]: Demonstrates secure handling of external data by providing code examples for validating API responses with Zod schemas and verifying webhook signatures using the verifyWebhookSignature utility.
  • [SAFE]: All documented network operations are standard SDK functions (e.g., fetch, client.request) used for communicating with the user's own Spree commerce API.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:12 PM
Security Audit — agent-trust-hub — spree-typescript-sdk