skills/vercel/shop/build-shop/Gen Agent Trust Hub

build-shop

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • Local Audit Script: The skill includes a Node.js script (scripts/audit-storefront.mjs) used to perform static analysis on the storefront codebase. This script scans for performance and best-practice hotspots, such as proper Next.js image usage and client boundary placement, without performing network operations or executing evaluated code.
  • Trusted External Resources: The skill references documentation and reference implementations exclusively from official Vercel domains and GitHub repositories. These resources are used to ground the agent's work in authoritative source patterns.
  • Standard Data Ingestion: The skill instructs the agent to read project-specific files like AGENTS.md and route source code to understand the implementation context. While this represents a surface for indirect prompt injection, it is a standard and necessary pattern for coding assistance skills and is handled within the agent's normal operational boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:50 PM
Security Audit — agent-trust-hub — build-shop