build-shop
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- Local Audit Script: The skill includes a Node.js script (
scripts/audit-storefront.mjs) used to perform static analysis on the storefront codebase. This script scans for performance and best-practice hotspots, such as proper Next.js image usage and client boundary placement, without performing network operations or executing evaluated code. - Trusted External Resources: The skill references documentation and reference implementations exclusively from official Vercel domains and GitHub repositories. These resources are used to ground the agent's work in authoritative source patterns.
- Standard Data Ingestion: The skill instructs the agent to read project-specific files like
AGENTS.mdand route source code to understand the implementation context. While this represents a surface for indirect prompt injection, it is a standard and necessary pattern for coding assistance skills and is handled within the agent's normal operational boundaries.
Audit Metadata