shopify-hydrogen

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes several utility scripts (search_shopify_docs.mjs, get_weaverse_page.mjs, search_weaverse_docs.mjs) that perform network requests to fetch the latest API documentation. These requests target shopify.dev (official Shopify documentation) and weaverse.io (the author's official domain), which are legitimate sources for this skill's functionality.
  • [COMMAND_EXECUTION]: The script scripts/check_docs_helpers.mjs uses node:child_process.spawnSync to run local tests against other scripts in the same folder. This is a controlled internal testing mechanism used to verify input sanitization and response handling logic.
  • [SAFE]: The documentation scripts implement strict validation using regular expressions to sanitize user-provided queries and paths, preventing potential injection or directory traversal attacks. No malicious behaviors such as credential exfiltration, obfuscation, or persistence were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:15 PM
Security Audit — agent-trust-hub — shopify-hydrogen