shopify-hydrogen
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes several utility scripts (
search_shopify_docs.mjs,get_weaverse_page.mjs,search_weaverse_docs.mjs) that perform network requests to fetch the latest API documentation. These requests targetshopify.dev(official Shopify documentation) andweaverse.io(the author's official domain), which are legitimate sources for this skill's functionality. - [COMMAND_EXECUTION]: The script
scripts/check_docs_helpers.mjsusesnode:child_process.spawnSyncto run local tests against other scripts in the same folder. This is a controlled internal testing mechanism used to verify input sanitization and response handling logic. - [SAFE]: The documentation scripts implement strict validation using regular expressions to sanitize user-provided queries and paths, preventing potential injection or directory traversal attacks. No malicious behaviors such as credential exfiltration, obfuscation, or persistence were detected.
Audit Metadata