setup-weaverse-project

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several shell commands to manage project initialization and environment setup. Evidence includes calls to git, npm, npx, node, gh, and shopify (SKILL.md). A curl command is used locally to verify server status during the verification phase (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes external tools including @weaverse/cli and @weaverse/mcp using npx. It also utilizes the Shopify CLI (shopify hydrogen) for environment and storefront management (SKILL.md).
  • [REMOTE_CODE_EXECUTION]: Remote code is executed via npx when running the Weaverse scaffolding CLI and the Model Context Protocol (MCP) server. These resources are vendor-owned tools belonging to the skill author (SKILL.md).
  • [CREDENTIALS_UNSAFE]: The skill handles sensitive variables such as PUBLIC_STOREFRONT_API_TOKEN and WEAVERSE_API_KEY. It mitigates risk by instructing the agent to generate SESSION_SECRET dynamically via a local cryptographic command and advising users to store API keys in environment blocks rather than tracked files (SKILL.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for injection where user-supplied inputs like WEAVERSE_PROJECT_ID are interpolated into shell commands.
  • Ingestion points: User-provided project IDs and theme handles (SKILL.md).
  • Boundary markers: No explicit delimiters are used for user inputs.
  • Capability inventory: Input variables are used in npx @weaverse/cli and directory creation commands (SKILL.md).
  • Sanitization: No specific sanitization logic is provided in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 06:44 AM
Security Audit — agent-trust-hub — setup-weaverse-project